cbcvebase.
CVE-2020-14815
published 2020-10-21

CVE-2020-14815: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions…

PriorityP350high8.2CVSS 3.1
AVNACLPRNUIRSCCHILAN
EPSS
8.22%
94.2th percentile
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

Affected

6 ranges
VendorProductVersion rangeFixed in
oraclebusiness_intelligence
oraclebusiness_intelligence
oraclebusiness_intelligence
oracle_corporationbusiness_intelligence_enterprise_edition
oracle_corporationbusiness_intelligence_enterprise_edition
oracle_corporationbusiness_intelligence_enterprise_edition

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability affects Oracle Business Intelligence Enterprise Edition via HTTP, is unauthenticated, and requires human interaction (consistent with XSS/injection via a crafted HTTP request). Monitor for anomalous unauthenticated HTTP requests targeting OBIEE Analytics Actions endpoints.
  • The vulnerability has a Changed scope (S:C) in the CVSS vector, indicating potential for cross-site scripting or similar client-side attack pivoting to impact additional products beyond OBIEE itself.
  • Affected component is Analytics Actions within Oracle Business Intelligence Enterprise Edition. Focus detection on HTTP traffic to Analytics Actions endpoints for versions 5.5.0.0.0, 12.2.1.3.0, and 12.2.1.4.0.
  • ·Exploitation requires human interaction from a person other than the attacker (e.g., a victim clicking a malicious link), which limits purely automated exploitation but is consistent with phishing-delivered attack chains.
  • ·Only three specific versions are confirmed affected: 5.5.0.0.0, 12.2.1.3.0, and 12.2.1.4.0. Detection and patching efforts should be scoped accordingly.

CVSS provenance

nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_oracle8.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.