← Back to browse · API

CVE-2020-2961

Severity
CRITICAL
CVSS
9.8
EPSS
0.01844
Risk score
39.85
CISA KEV
No
PoC
No
Published
2020-04-15
Modified
2024-09-27
First seen
2026-08-07
Aliases
EUVD-2020-22754, GHSA-XPM5-W5VX-3XW6
Products
Oracle Corporation:Enterprise Manager Base Platform 13.2.0.0, Oracle Corporation:Enterprise Manager Base Platform 13.3.0.0
Sources
euvd EUVD-2020-22754

Description

Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framework (Oracle OHS)). Supported versions that are affected are 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Enterprise Manager Base Platform. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

References