CVE-2020-14864
published 2020-10-21CVE-2020-14864: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are…
PriorityP192high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-07-18
Exploited in the wild
EPSS
97.23%
99.9th percentile
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle_corporation | business_intelligence_enterprise_edition | — | — |
| oracle_corporation | business_intelligence_enterprise_edition | — | — |
| oracle_corporation | business_intelligence_enterprise_edition | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit targets the 'getPreviewImage' endpoint via the 'previewFilePath' URL parameter for directory traversal/LFI. Monitor HTTP GET requests to /analytics/saw.dll containing 'getPreviewImage' and 'previewFilePath' with path traversal sequences. ↗
- →Successful exploitation returns file contents (e.g., /etc/passwd) in the HTTP 200 response body. Detect responses matching 'root:.*:0:0:' pattern from the analytics endpoint. ↗
- →Use Shodan/FOFA to identify exposed Oracle BI instances as potential targets: search for http.title:'oracle business intelligence sign in'. ↗
- →The vulnerability is unauthenticated and exploitable over HTTP with no user interaction required (CVSS AV:N/AC:L/PR:N/UI:N), meaning no authentication headers are needed in the malicious request. ↗
- ·Affected versions are 5.5.0.0.0, 12.2.1.3.0, and 12.2.1.4.0 only. Detection rules should be scoped to these versions to reduce false positives. ↗
- ·The vulnerability is in the Installation component and was tested on SUSE Linux Enterprise Server; path traversal payloads targeting Linux file paths (e.g., /etc/passwd) are most relevant for detection. ↗
- ·This CVE is listed in CISA's Known Exploited Vulnerabilities catalog with a remediation due date of 2022-07-18, indicating active in-the-wild exploitation. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
vulncheck7.5HIGH
cisa7.5HIGH
vendor_oracle7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p833-99r6-7hqr: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation)
ghsa_unreviewed·2022-05-24
CVE-2020-14864 [HIGH] CWE-22 GHSA-p833-99r6-7hqr: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation)
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
VulnCheck
Oracle Business Intelligence Enterprise Edition Path Transversal
vulncheck·2020·CVSS 7.5
CVE-2020-14864 [HIGH] CWE-22 Oracle Business Intelligence Enterprise Edition Path Transversal
Oracle Business Intelligence Enterprise Edition Path Transversal
Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file.
Affected: Oracle Intelligence Enterprise Edition
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2024-01-22&host_type=src&vulnerability=cve-2020-14864; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2024-01-23&host_type=src&vulnerability=cve-2020-14864; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2024-01-24
CISA
Oracle Business Intelligence Enterprise Edition Path Transversal
cisa·2022-01-18·CVSS 7.5
CVE-2020-14864 [HIGH] CWE-22 Oracle Business Intelligence Enterprise Edition Path Transversal
Vulnerability: Oracle Business Intelligence Enterprise Edition Path Transversal
Affected: Oracle Intelligence Enterprise Edition
Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-14864
Remediation Due Date: 2022-07-18
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Installation — CVE-2020-14864
vendor_oracle·2020-10-15·CVSS 7.5
CVE-2020-14864 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Installation — CVE-2020-14864
Oracle Oracle Fusion Middleware Risk Matrix: Installation vulnerability
CVE: CVE-2020-14864
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
No detection rules found.
Exploit-DB
Oracle Business Intelligence Enterprise Edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 - 'getPreviewImage' Directory Traversal/Local File Inclusion
exploitdb·2020-10-28·CVSS 7.5
CVE-2020-14864 [HIGH] Oracle Business Intelligence Enterprise Edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 - 'getPreviewImage' Directory Traversal/Local File Inclusion
Oracle Business Intelligence Enterprise Edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 - 'getPreviewImage' Directory Traversal/Local File Inclusion
---
# Exploit Title: Oracle Business Intelligence Enterprise Edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 - 'getPreviewImage' Directory Traversal/Local File Inclusion
# Date: 2020-10-27
# Exploit Author: Ivo Palazzolo (@palaziv)
# Reference: https://www.oracle.com/security-alerts/cpuoct2020.html
# Vendor Homepage: https://www.oracle.com
# Software Link: https://www.oracle.com/middleware/technologies/bi-enterprise-edition-downloads.html
# Version: 5.5.0.0.0, 12.2.1.3.0, 12.2.1.4.0
# Tested on: SUSE Linux Enterprise Server
# CVE: CVE-2020-14864
# Description
A Directory Traversal vulnerability has been discovered in the 'getPreviewImage' function
Nuclei
Oracle Fusion - Directory Traversal/Local File Inclusion
nuclei·CVSS 7.5
CVE-2020-14864 [HIGH] Oracle Fusion - Directory Traversal/Local File Inclusion
Oracle Fusion - Directory Traversal/Local File Inclusion
Oracle Business Intelligence Enterprise Edition 5.5.0.0.0, 12.2.1.3.0, and 12.2.1.4.0 are vulnerable to local file inclusion vulnerabilities via "getPreviewImage."
Template:
id: CVE-2020-14864
info:
name: Oracle Fusion - Directory Traversal/Local File Inclusion
author: Ivo Palazzolo (@palaziv)
severity: high
description: Oracle Business Intelligence Enterprise Edition 5.5.0.0.0, 12.2.1.3.0, and 12.2.1.4.0 are vulnerable to local file inclusion vulnerabilities via "getPreviewImage."
impact: |
Successful exploitation of this vulnerability could allow an attacker to read sensitive files, execute arbitrary code, or gain unauthorized access to the system.
remediation: |
Apply the latest security patches and updates provided by Oracle
Unit42
Network Attack Trends: Internet of Threats (November 2020-January 2021)
blogs_unit42·2021-04-12·CVSS 7.5
CVE-2020-28188 [HIGH] Network Attack Trends: Internet of Threats (November 2020-January 2021)
# Executive Summary
Unit 42 researchers analyzed network attack trends over Winter 2020 and discovered many interesting exploits in the wild. During the period of Nov. 2020 to Jan. 2021, the majority of the attacks we observed were classified as critical (75%), compared to the 50.4% we reported in the fall of 2020. Several newly observed exploits, including CVE-2020-28188, CVE-2020-17519, and CVE-2020-29227, have emerged and were continuously being exploited in the wild as of late 2020 to early 2021.
This blog provides details of the newly observed exploits as well as a dive deep into the exploitation analysis, vendor analysis, attack origin, and attack category distribution.
Palo Alto Networks Next-Generation Firewall customers are protected from these attacks with the URL Filtering an
Unit42
Network Attack Trends: Internet of Threats (November 2020-January 2021)
blogs_unit42·2021-04-12·CVSS 7.5
[HIGH] Network Attack Trends: Internet of Threats (November 2020-January 2021)
Threat Research Center
Trend Reports
Vulnerabilities
## Network Attack Trends: Internet of Threats (November 2020-January 2021)
Lei Xu
Yue Guan
Vaibhav Singhal
Published: April 12, 2021
Malware
Trend Reports
Vulnerabilities
Botnet
DDoS
Exploit kit
IoT
Network security trends
## Executive Summary
Unit 42 researchers analyzed network attack trends over Winter 2020 and discovered many interesting exploits in the wild. During the period of Nov. 2020 to Jan. 2021, the majority of the attacks we observed were classified as critical (75%), compared to the 50.4% we reported in the fall of 2020 . Several newly observed exploits, including CVE-2020-28188 , CVE-2020-17519 , and CVE-2020-29227 , have emerged and were continuously being exploited in the wild as of late 2020 to earl
http://packetstormsecurity.com/files/159748/Oracle-Business-Intelligence-Enterprise-Edition-5.5.0.0.0-12.2.1.3.0-12.2.1.4.0-LFI.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttp://packetstormsecurity.com/files/159748/Oracle-Business-Intelligence-Enterprise-Edition-5.5.0.0.0-12.2.1.3.0-12.2.1.4.0-LFI.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-14864
2020-10-21
Published
2022-01-18
Added to CISA KEV
Exploited in the wild