Demonstrating CVE-2020-2883 Version 3: Remote Code Execution in the Oracle BI Virtual Appliance

Опубликовано: 11 Май 2020
на канале: Zero Day Initiative
1,581
14

This video demonstrates how an unauthenticated attacker could execute commands on affected versions of the Oracle Business Intelligence Virtual Appliance. This vulnerability resides in "BIRemotingServlet", which listens on port TCP port 7780 and does not require any authentication.

For full details on the vulnerability, see the blog at https://www.zerodayinitiative.com/blo...