Skip to content
COOEY

EXPOSURES › CVE-2020-14864

CVE-2020-14864

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-01-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-14864 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Oracle Business Intelligence Enterprise Edition suffered a path traversal vulnerability allowing attackers to read arbitrary system files via the getPreviewImage function.

An attacker could exploit the path traversal flaw in Oracle Business Intelligence Enterprise Edition to access sensitive system files, potentially exposing credentials or configuration data. This unpatched vulnerability was actively exploited in the wild, highlighting the risk of relying on known CVEs without timely remediation. DIB organizations must ensure all Oracle BI EE instances are patched and monitored for exploitation attempts.

Shame score — A known path traversal vulnerability was actively exploited in the wild, indicating negligence in patch management and leaving systems exposed to data exfiltration.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file.

AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized