cbcvebase.
CVE-2020-14864
published 2020-10-21

CVE-2020-14864: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are…

PriorityP192high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-07-18
Exploited in the wild
EPSS
97.23%
99.9th percentile
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Affected

6 ranges
VendorProductVersion rangeFixed in
oraclebusiness_intelligence
oraclebusiness_intelligence
oraclebusiness_intelligence
oracle_corporationbusiness_intelligence_enterprise_edition
oracle_corporationbusiness_intelligence_enterprise_edition
oracle_corporationbusiness_intelligence_enterprise_edition

Detection & IOCsextracted from sources · hover to see the quote

url/analytics/saw.dll?getPreviewImage&previewFilePath=/etc/passwd
url/analytics/saw.dll?bieehome&startPage=1
url/analytics/saw.dll?getPreviewImage&previewFilePath=/etc/passwd
  • Exploit targets the 'getPreviewImage' endpoint via the 'previewFilePath' URL parameter for directory traversal/LFI. Monitor HTTP GET requests to /analytics/saw.dll containing 'getPreviewImage' and 'previewFilePath' with path traversal sequences.
  • Successful exploitation returns file contents (e.g., /etc/passwd) in the HTTP 200 response body. Detect responses matching 'root:.*:0:0:' pattern from the analytics endpoint.
  • Use Shodan/FOFA to identify exposed Oracle BI instances as potential targets: search for http.title:'oracle business intelligence sign in'.
  • The vulnerability is unauthenticated and exploitable over HTTP with no user interaction required (CVSS AV:N/AC:L/PR:N/UI:N), meaning no authentication headers are needed in the malicious request.
  • ·Affected versions are 5.5.0.0.0, 12.2.1.3.0, and 12.2.1.4.0 only. Detection rules should be scoped to these versions to reduce false positives.
  • ·The vulnerability is in the Installation component and was tested on SUSE Linux Enterprise Server; path traversal payloads targeting Linux file paths (e.g., /etc/passwd) are most relevant for detection.
  • ·This CVE is listed in CISA's Known Exploited Vulnerabilities catalog with a remediation due date of 2022-07-18, indicating active in-the-wild exploitation.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
vulncheck7.5HIGH
cisa7.5HIGH
vendor_oracle7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.