## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-TUO4N8-CVE-2020-2950
# Oracle-BI (CVE-2020-2950)
## AMF डिसीरियलाइज़
> **संस्करण:** 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0
>
> **इंस्टॉल:** https://www.sql.edu.vn/obiee/oracle-business-intelligence-12c/
>
> **रेफ़:** https://peterjson.medium.com/cve-2020-2950-turning-amf-deserialize-bug-to-java-deserialize-bug-2984a8542b6f
* * *
* * *
## एक्सप्लॉइट - PoC
> amf.bin
>
> हेडर cmd बेस64 और चाइल्ड के साथ !!

* * *
## डीबग ट्रेस बग
URL: `/analytics/jbips/messagebroker/cs/`
* अनुरोध को हैंडल करें -> processCall()
