CVE-2020-14864
Oracle Business Intelligence Enterprise Edition Path Transversal
Record summary
CVE-2020-14864 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template. CISA lists CVE-2020-14864 in KEV.
Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Exploitation context
Known exploitation
- CISA KEV
- Listed · Jan 18, 2022 · CISA
- VulnCheck KEV
- Listed · Jan 18, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 26, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Intelligence Enterprise EditionBrowse Oracle / Intelligence Enterprise Edition | CISA | Version data not supplied | |
Business Intelligence Enterprise EditionBrowse Oracle Corporation / Business Intelligence Enterprise Edition | CVE List | 5.5.0.0.0 | affected |
| 12.2.1.3.0 | affected | ||
| 12.2.1.4.0 | affected | ||
Proofs of concept
1Catalogued exploits
ExploitDBOracle Business Intelligence Enterprise Edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 - 'getPreviewImage' Directory Traversal/Local File InclusionExploitDB exploitby Ivo PalazzoloNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHOracle Fusion - Directory Traversal/Local File InclusionCVSS 7.5
Oracle Business Intelligence Enterprise Edition 5.5.0.0.0, 12.2.1.3.0, and 12.2.1.4.0 are vulnerable to local file inclusion vulnerabilities via "getPreviewImage."
Impact
Successful exploitation of this vulnerability could allow an attacker to read sensitive files, execute arbitrary code, or gain unauthorized access to the system.
Remediation
Apply the latest security patches and updates provided by Oracle to fix this vulnerability.
Source: ProjectDiscovery