CVE-2020-2737
Last modified
CVE-2020-2737 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. EPSS estimates a 1.03% chance of exploitation in the next 30 days.
Description
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows high privileged attacker having Create Session, Execute Catalog Role privilege with network access via Oracle Net to compromise Core RDBMS. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Core RDBMS. CVSS 3.0 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).
Metrics
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Database Server | 11.2.0.4 |
| Oracle | Database Server | 12.1.0.2 |
| Oracle | Database Server | 12.2.0.1 |
| Oracle | Database Server | 18c |
| Oracle | Database Server | 19c |
References
- https://www.oracle.com/security-alerts/cpuapr2020.htmlVendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-2737?
How severe is CVE-2020-2737?
How do I fix CVE-2020-2737?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-27358An issue was discovered in REDCap 8.11.6 through 9.x before …4.3
- CVE-2020-27359A cross-site scripting (XSS) issue in REDCap 8.11.6 through …5.4
- CVE-2020-27361An issue exists within Akkadian Provisioning Manager 4.50.02…7.5
- CVE-2020-27362An issue exists within the SSH console of Akkadian Provision…8.8
- CVE-2020-27366Cross Site Scripting (XSS) vulnerability in wlscanresults.ht…6.1
- CVE-2020-27368Directory Indexing in Login Portal of Login Portal of TOTOLI…5.5
- CVE-2020-27372A buffer overflow vulnerability exists in Brandy Basic V Int…9.8
- CVE-2020-27373Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 …8.8
- CVE-2020-27374Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 …7.5
- CVE-2020-27375Dr Trust USA iCheck Connect BP Monitor BP Testing 118 versio…6.5
- CVE-2020-27376Dr Trust USA iCheck Connect BP Monitor BP Testing 118 versio…8.8
- CVE-2020-27377A cross-site scripting (XSS) vulnerability was discovered in…4.8
Are you affected by CVE-2020-2737?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
