tuo4n8 / CVE-2020-2950

5 stars 0 forks source link

Oracle-BI (CVE-2020-2950)

AMF deseiralize

Version: 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0

Install:https://www.sql.edu.vn/obiee/oracle-business-intelligence-12c/

Ref: https://peterjson.medium.com/cve-2020-2950-turning-amf-deserialize-bug-to-java-deserialize-bug-2984a8542b6f



Exploit - PoC

amf.bin

Header cmd with base64 and child !!


Debug trace bug

URL: /analytics/jbips/messagebroker/cs/

image-20210521104317854

image-20210521104423834

image-20210521104538758

image-20210521104730919

image-20210521104755256

image-20210521104844150

image-20210521104956342

image-20210521105409912

image-20210521105523270