Improper input validation in Oracle Application Express - CVE-2020-9281

 

Improper input validation in Oracle Application Express - CVE-2020-9281

Published: October 21, 2020


Vulnerability identifier: #VU47770
CSH Severity: Medium
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2020-9281
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to read and manipulate data.

The vulnerability exists due to improper input validation within the Oracle Application Express in Oracle Database Server. A remote authenticated user can exploit this vulnerability to read and manipulate data.


Affected software

Oracle Application Express
Oracle Banking Enterprise Default Management
IBM Sterling Partner Engagement Manager
Engineering Workflow Management
PeopleSoft Enterprise PeopleTools
JD Edwards EnterpriseOne Tools
Oracle Agile PLM Framework
IBM Engineering Requirements Management DOORS Next
Oracle WebCenter Portal
Ubuntu
ckeditor (Ubuntu package)

How to mitigate CVE-2020-9281

Install updates from vendor's website.

Oracle Application Express - update to 20.2
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
JD Edwards EnterpriseOne Tools - update to 9.2.5.2
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
ckeditor (Ubuntu package) - addressed in versions 4.5.7+dfsg-2ubuntu0.18.04.1, 4.12.1+dfsg-1ubuntu0.1, 4.16.0+dfsg-2ubuntu0.1
Engineering Workflow Management - addressed in versions 7.0.1 iFix021, 7.0.2 iFix021

External References

Related Security Bulletins