CVE-2020-14864

HIGH KEV NUCLEI

Oracle Business Intelligence Enterprise Edition - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2020-14864 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added January 18, 2022. EIP tracks 1 public exploit from researchers including Ivo Palazzolo. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in Oracle Business Intelligence Enterprise Edition via the 'getPreviewImage' function. By manipulating the 'previewFilePath' parameter, an attacker can read arbitrary system files, such as '/etc/passwd'.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Exploits (1)

exploitdb WORKING POC
by Ivo Palazzolo · textwebappslinux
https://www.exploit-db.com/exploits/48964

This exploit demonstrates a directory traversal vulnerability in Oracle Business Intelligence Enterprise Edition via the 'getPreviewImage' function. By manipulating the 'previewFilePath' parameter, an attacker can read arbitrary system files, such as '/etc/passwd'.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Oracle Business Intelligence Enterprise Edition 5.5.0.0.0, 12.2.1.3.0, 12.2.1.4.0
Auth required
Prerequisites: Access to the administration interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Oracle Fusion - Directory Traversal/Local File Inclusion
HIGHby Ivo Palazzolo (@palaziv)
Shodan: http.title:"oracle business intelligence sign in"
FOFA: title="oracle business intelligence sign in"

Scores

CVSS v3 7.5
EPSS 0.9402
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact partial

Details

CISA KEV 2022-01-18
VulnCheck KEV 2022-01-18
InTheWild.io 2021-04-12
ENISA EUVD EUVD-2020-7000
CWE
CWE-22
Status published
Products (3)
oracle/business_intelligence 5.5.0.0.0
oracle/business_intelligence 12.2.1.3.0
oracle/business_intelligence 12.2.1.4.0
Published Oct 21, 2020
KEV Added Jan 18, 2022
Tracked Since Feb 18, 2026