CVE-2020-14864
HIGH KEV NUCLEIOracle Business Intelligence Enterprise Edition - Info Disclosure
Title source: llmDescription
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Exploits (1)
Nuclei Templates (1)
Oracle Fusion - Directory Traversal/Local File Inclusion
HIGHby Ivo Palazzolo (@palaziv)
Shodan:
http.title:"oracle business intelligence sign in"
FOFA:
title="oracle business intelligence sign in"
References (3)
Scores
CVSS v3
7.5
EPSS
0.9402
EPSS Percentile
99.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CISA KEV
2022-01-18
VulnCheck KEV
2022-01-18
InTheWild.io
2021-04-12
ENISA EUVD
EUVD-2020-7000
CWE
CWE-22
Status
published
Products (3)
oracle/business_intelligence
5.5.0.0.0
oracle/business_intelligence
12.2.1.3.0
oracle/business_intelligence
12.2.1.4.0
Published
Oct 21, 2020
KEV Added
Jan 18, 2022
Tracked Since
Feb 18, 2026