First published: Wed Oct 21 2020(Updated: )
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Business Intelligence Enterprise Edition | ||
Oracle Business Intelligence Enterprise Edition | =5.5.0.0.0 | |
Oracle Business Intelligence Enterprise Edition | =12.2.1.3.0 | |
Oracle Business Intelligence Enterprise Edition | =12.2.1.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14864 is a vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware that allows a remote attacker to perform path traversal and read arbitrary files.
CVE-2020-14864 has a severity rating of 7.5 (High).
CVE-2020-14864 affects Oracle Business Intelligence Enterprise Edition versions 5.5.0.0.0, 12.2.1.3.0, and 12.2.1.4.0.
An attacker with network access can exploit CVE-2020-14864 by performing path traversal attacks to read arbitrary files on the target system.
Yes, Oracle has released patches to address CVE-2020-14864. It is recommended to apply the latest patches as soon as possible to mitigate the vulnerability.