CVE-2020-14864
HIGH KEV NUCLEIOracle Business Intelligence Enterprise Edition - Info Disclosure
Title source: llmExploitation Summary
CVE-2020-14864 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added January 18, 2022. EIP tracks 1 public exploit from researchers including Ivo Palazzolo. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in Oracle Business Intelligence Enterprise Edition via the 'getPreviewImage' function. By manipulating the 'previewFilePath' parameter, an attacker can read arbitrary system files, such as '/etc/passwd'.
Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in Oracle Business Intelligence Enterprise Edition via the 'getPreviewImage' function. By manipulating the 'previewFilePath' parameter, an attacker can read arbitrary system files, such as '/etc/passwd'.
Nuclei Templates (1)
http.title:"oracle business intelligence sign in"
title="oracle business intelligence sign in"
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N