Improper input validation in Oracle WebLogic Server - CVE-2020-6950

 

Improper input validation in Oracle WebLogic Server - CVE-2020-6950

Published: February 7, 2020


Vulnerability identifier: #VU25052
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-6950
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Web Container (JavaServer Faces) component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to gain access to sensitive information.


Affected software

Oracle WebLogic Server
Oracle Solaris Cluster
openEuler
Oracle Communications Network Integrity
Oracle Communications Pricing Design Center
Oracle Time and Labor
Oracle Communications User Data Repository
Oracle Retail Customer Insights
mojarra
mojarra-javadoc
Red Hat Single Sign-On
Oracle Hyperion Calculation Manager

How to mitigate CVE-2020-6950

Install updates from vendor's website.

mojarra - update to 2.2.13-2
mojarra-javadoc - update to 2.2.13-2
Red Hat Single Sign-On - update to 7.3.8
Oracle Hyperion Calculation Manager - update to 11.2.8.0

External References

Related Security Bulletins