ZeroHour

CVE-2020-14864

KEVlarge

Unauthenticated Path Traversal in Oracle Business Intelligence Enterprise Edition

CISA: Oracle Business Intelligence Enterprise Edition Path Transversal

CVSS 3.1
7.5 high
EPSS
97%p100
Published
()
KEV added
AI analysis

Oracle Business Intelligence Enterprise Edition (OBIEE) contains a path traversal flaw (CWE-22) in its Installation component, affecting versions 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. An unauthenticated attacker with network access over HTTP can send crafted requests containing directory traversal sequences to reach files or data outside the intended path. Successful exploitation results in unauthorized access to critical data, potentially all OBIEE-accessible data, with confidentiality-only impact per the CVSS vector (C:H/I:N/A:N). The vulnerability is easily exploitable and requires no privileges or user interaction. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-01-18, confirming exploitation in the wild, and EPSS assigns a 97.2% probability of exploitation within 30 days, although no public proof-of-concept is known.

What to do: Apply Oracle's October 2020 Critical Patch Update (or a later CPU) for OBIEE 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0, as required by the CISA KEV catalog action. Until patched, restrict HTTP access to OBIEE servers to trusted networks and review access logs for directory traversal patterns. Because exploitation is confirmed in the wild, prioritize internet-exposed BI instances and verify no unauthorized data access has occurred.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Fusion Middleware, Installation component)5.5.0.0.0, 12.2.1.3.0, 12.2.1.4.0
Estimated exposure
largetens of thousands of OBIEE deployments worldwide, of which likely thousands are internet-exposed — OBIEE is a long-standing enterprise analytics platform deployed across large enterprises and government agencies, and public internet scans typically show thousands of exposed instances while the total installed base including…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CISA Known Exploited Vulnerability
Affected
Oracle Intelligence Enterprise Edition
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
oracle
Products
business intelligence
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news