EXPOSURES › CVE-2020-14864
CVE-2020-14864
HIGH ⌖ ON CISA KEV · EXPLOITEDOracle Business Intelligence Enterprise Edition suffered a path traversal vulnerability allowing attackers to read arbitrary system files via the getPreviewImage function.
An attacker could exploit the path traversal flaw in Oracle Business Intelligence Enterprise Edition to access sensitive system files, potentially exposing credentials or configuration data. This unpatched vulnerability was actively exploited in the wild, highlighting the risk of relying on known CVEs without timely remediation. DIB organizations must ensure all Oracle BI EE instances are patched and monitored for exploitation attempts.
Shame score — A known path traversal vulnerability was actively exploited in the wild, indicating negligence in patch management and leaving systems exposed to data exfiltration.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |