CVE-2020-14815
published 2020-10-21CVE-2020-14815: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions…
PriorityP350high8.2CVSS 3.1
AVNACLPRNUIRSCCHILAN
EPSS
8.22%
94.2th percentile
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle_corporation | business_intelligence_enterprise_edition | — | — |
| oracle_corporation | business_intelligence_enterprise_edition | — | — |
| oracle_corporation | business_intelligence_enterprise_edition | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability affects Oracle Business Intelligence Enterprise Edition via HTTP, is unauthenticated, and requires human interaction (consistent with XSS/injection via a crafted HTTP request). Monitor for anomalous unauthenticated HTTP requests targeting OBIEE Analytics Actions endpoints. ↗
- →The vulnerability has a Changed scope (S:C) in the CVSS vector, indicating potential for cross-site scripting or similar client-side attack pivoting to impact additional products beyond OBIEE itself. ↗
- →Affected component is Analytics Actions within Oracle Business Intelligence Enterprise Edition. Focus detection on HTTP traffic to Analytics Actions endpoints for versions 5.5.0.0.0, 12.2.1.3.0, and 12.2.1.4.0. ↗
- ·Exploitation requires human interaction from a person other than the attacker (e.g., a victim clicking a malicious link), which limits purely automated exploitation but is consistent with phishing-delivered attack chains. ↗
- ·Only three specific versions are confirmed affected: 5.5.0.0.0, 12.2.1.3.0, and 12.2.1.4.0. Detection and patching efforts should be scoped accordingly. ↗
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_oracle8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9h8f-4c68-rhj4: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions)
ghsa_unreviewed·2022-05-24
CVE-2020-14815 [HIGH] GHSA-9h8f-4c68-rhj4: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions)
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized u
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Analytics Actions — CVE-2020-14815
vendor_oracle·2020-10-15·CVSS 8.2
CVE-2020-14815 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Analytics Actions — CVE-2020-14815
Oracle Oracle Fusion Middleware Risk Matrix: Analytics Actions vulnerability
CVE: CVE-2020-14815
CVSS: 8.2
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-10-21
Published