Security readout for executives and security teams
Plain-English summary
CVE-2020-14741 can let a privileged database user crash or hang Oracle Database Filesystem. It does not indicate data theft or data modification, but it can disrupt availability of DBFS-dependent services. Urgency is moderate because exploitation requires significant database privileges and Oracle Net access.
Executive priority
Treat this as a moderate availability risk for affected Oracle environments. Prioritize patch confirmation and privilege review where DBFS supports business processes or where privileged database access is broadly distributed.
Technical view
The flaw affects Oracle Database Enterprise Edition 11.2.0.4, 12.1.0.2, and 12.2.0.1 in the Database Filesystem component. CVSS 3.1 is 4.9 with network attack vector, low complexity, high privileges required, no user interaction, and high availability impact only.
Likely exposure
Exposure is most likely where affected Oracle Database Enterprise Edition versions use Database Filesystem and allow Oracle Net access to users holding Resource, Create Table, Create View, Create Procedure, and DBFS role privileges.
Exploitation context
The source bundle does not show CISA KEV listing or cited active exploitation. The described attack requires a high-privileged database user with network access via Oracle Net. Successful exploitation can repeatedly crash or hang Database Filesystem, causing denial of service.
Researcher notes
No CWE is provided in the source bundle. The key constraints are PR:H and availability-only impact. Validation should focus on affected version presence, DBFS usage, Oracle Net reachability, and whether users hold the listed privilege combination.
Mitigation direction
- Apply Oracle's October 2020 Critical Patch Update or later vendor guidance for affected Oracle Database deployments.
- Inventory Oracle Database Enterprise Edition versions 11.2.0.4, 12.1.0.2, and 12.2.0.1.
- Restrict Oracle Net access to trusted administrative paths only.
- Remove unnecessary Resource, Create Table, Create View, Create Procedure, and DBFS role grants.
- Monitor Database Filesystem availability for repeated crashes or hangs.
Validation and detection
- Confirm whether Oracle Database Filesystem is deployed on affected Enterprise Edition versions.
- Review privileged database accounts for the named role and object-creation privileges.
- Verify Oracle CPU remediation status through patch inventory or vendor-supported tooling.
- Check network controls limiting Oracle Net access to the database service.
- Review operational logs for DBFS hangs, crashes, or recurring availability incidents.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Database behavior lookup
The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2020-14741 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 4.9 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H1.23.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
4.9MediumVector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Source materials
- CVE List V5 sourceCVE List V5
- https://www.oracle.com/security-alerts/cpuoct2020.htmlCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
