Multiple vulnerabilities in Oracle Enterprise Manager Base Platform



| Updated: 2020-01-26
Risk Medium
Patch available YES
Number of vulnerabilities 33
CVE-ID CVE-2020-2628
CVE-2020-2639
CVE-2020-2625
CVE-2020-2613
CVE-2020-2630
CVE-2020-2622
CVE-2020-2629
CVE-2020-2643
CVE-2020-2623
CVE-2020-2635
CVE-2020-2646
CVE-2020-2632
CVE-2020-2608
CVE-2020-2615
CVE-2020-2644
CVE-2020-2616
CVE-2020-2621
CVE-2020-2624
CVE-2020-2633
CVE-2020-2642
CVE-2020-2634
CVE-2020-2626
CVE-2020-2631
CVE-2020-2636
CVE-2020-2645
CVE-2020-2617
CVE-2020-2619
CVE-2020-2620
CVE-2020-2618
CVE-2020-2612
CVE-2020-2610
CVE-2020-2611
CVE-2020-2609
CWE-ID CWE-20
Exploitation vector Network
Public exploit N/A
Vulnerable software
Enterprise Manager Base Platform
Server applications / Other server solutions

Vendor Oracle

Security Bulletin

This security bulletin contains information about 33 vulnerabilities.

1) Improper input validation

EUVDB-ID: #VU24622

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2628

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Host Management component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Improper input validation

EUVDB-ID: #VU24623

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2639

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Host Management component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Improper input validation

EUVDB-ID: #VU24624

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2625

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Job System component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Improper input validation

EUVDB-ID: #VU24621

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2613

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Global EM Framework component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

5) Improper input validation

EUVDB-ID: #VU24620

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2630

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Extensibility Framework component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

6) Improper input validation

EUVDB-ID: #VU24618

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2622

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Event Management component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

7) Improper input validation

EUVDB-ID: #VU24619

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2629

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Extensibility Framework component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

8) Improper input validation

EUVDB-ID: #VU24625

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2643

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Job System component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

9) Improper input validation

EUVDB-ID: #VU24626

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2623

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Metrics Framework component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

10) Improper input validation

EUVDB-ID: #VU24631

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2635

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the System Monitoring component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

11) Improper input validation

EUVDB-ID: #VU24637

Risk: Medium

CVSSv4.0: 1.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2646

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote authenticated user to read and manipulate data.

The vulnerability exists due to improper input validation within the Command Line Interface component in Enterprise Manager Base Platform. A remote authenticated user can exploit this vulnerability to read and manipulate data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

12) Improper input validation

EUVDB-ID: #VU24630

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2632

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the System Monitoring component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

13) Improper input validation

EUVDB-ID: #VU24629

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2608

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Repository component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 13.2.0.0 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

14) Improper input validation

EUVDB-ID: #VU24627

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2615

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Oracle Management Service component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

15) Improper input validation

EUVDB-ID: #VU24628

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2644

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Oracle Management Service component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

16) Improper input validation

EUVDB-ID: #VU24617

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2616

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Enterprise Manager Repository component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

17) Improper input validation

EUVDB-ID: #VU24616

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2621

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Enterprise Config Management component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

18) Improper input validation

EUVDB-ID: #VU24605

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2624

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Connector Framework component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

19) Improper input validation

EUVDB-ID: #VU24606

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2633

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Connector Framework component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

20) Improper input validation

EUVDB-ID: #VU24607

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2642

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Connector Framework component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

21) Improper input validation

EUVDB-ID: #VU24604

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2634

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Configuration Standard Framewk component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

22) Improper input validation

EUVDB-ID: #VU24603

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2626

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Cloud Control Manager - OMS component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

23) Improper input validation

EUVDB-ID: #VU24601

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2631

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Application Service Level Mgmt component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

24) Improper input validation

EUVDB-ID: #VU24602

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2636

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Application Service Level Mgmt component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

25) Improper input validation

EUVDB-ID: #VU24608

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2645

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Connector Framework component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

26) Improper input validation

EUVDB-ID: #VU24609

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2617

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Discovery Framework component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

27) Improper input validation

EUVDB-ID: #VU24614

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2619

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Enterprise Config Management component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

28) Improper input validation

EUVDB-ID: #VU24615

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2620

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Enterprise Config Management component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

29) Improper input validation

EUVDB-ID: #VU24613

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2618

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Enterprise Config Management component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

30) Improper input validation

EUVDB-ID: #VU24612

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2612

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Enterprise Config Management component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

31) Improper input validation

EUVDB-ID: #VU24610

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2610

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Enterprise Config Management component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

32) Improper input validation

EUVDB-ID: #VU24611

Risk: Medium

CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2611

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote privileged user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Enterprise Config Management component in Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to read, manipulate or delete data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

33) Improper input validation

EUVDB-ID: #VU24600

Risk: Medium

CVSSv4.0: 1.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-2609

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote authenticated user to read and manipulate data.

The vulnerability exists due to improper input validation within the Enterprise Config Management component in Enterprise Manager Base Platform. A remote authenticated user can exploit this vulnerability to read and manipulate data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Enterprise Manager Base Platform: 12.1.0.5 - 13.3.0.0

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujan2020.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###