Junglewise Threat Intelligence

CVE-2020-14864: Oracle Business Intelligence Enterprise Edition Path Transversal

CVE-2020-14864 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-01-18

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

A path traversal vulnerability in Oracle Business Intelligence Enterprise Edition allows unauthenticated attackers to access arbitrary system files via the preview FilePath parameter of the getPreviewImage function. Successful exploitation can lead to unauthorized access to critical data or complete access to all data accessible by the application.

Affected products

  • Oracle Business Intelligence Enterprise Edition 5.5.0.0.0, 12.2.1.3.0, 12.2.1.4.0

Timeline

  • 2020-10-21: disclosed: NVD Published Date
  • 2022-01-18: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog