CVE-2020-14864
KEVlargeUnauthenticated Path Traversal in Oracle Business Intelligence Enterprise Edition
CISA: Oracle Business Intelligence Enterprise Edition Path Transversal
Oracle Business Intelligence Enterprise Edition (OBIEE) contains a path traversal flaw (CWE-22) in its Installation component, affecting versions 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. An unauthenticated attacker with network access over HTTP can send crafted requests containing directory traversal sequences to reach files or data outside the intended path. Successful exploitation results in unauthorized access to critical data, potentially all OBIEE-accessible data, with confidentiality-only impact per the CVSS vector (C:H/I:N/A:N). The vulnerability is easily exploitable and requires no privileges or user interaction. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-01-18, confirming exploitation in the wild, and EPSS assigns a 97.2% probability of exploitation within 30 days, although no public proof-of-concept is known.
What to do: Apply Oracle's October 2020 Critical Patch Update (or a later CPU) for OBIEE 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0, as required by the CISA KEV catalog action. Until patched, restrict HTTP access to OBIEE servers to trusted networks and review access logs for directory traversal patterns. Because exploitation is confirmed in the wild, prioritize internet-exposed BI instances and verify no unauthorized data access has occurred.
| Oracle Business Intelligence Enterprise Edition (Oracle Fusion Middleware, Installation component) | 5.5.0.0.0, 12.2.1.3.0, 12.2.1.4.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
- Affected
- Oracle Intelligence Enterprise Edition
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- oracle
- Products
- business intelligence
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N