CVE-2020-14864 is a directory traversal/local file inclusion vulnerability affecting Oracle Business Intelligence Enterprise Edition versions 5.5.0.0.0, 12.2.1.3.0, and 12.2.1.4.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to gain unauthorized access to critical or all accessible data within the affected system. With a CVSS score of 7.5 (High), the attack requires no user interaction and can lead to complete confidentiality compromise. This CVE is actively exploited, listed in CISA's KEV catalog, and has publicly available exploit code, including an ExploitDB entry and Nuclei templates, indicating significant community interest and a high risk of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.5.0.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:business_intelligence:5.5.0.0.0:*:*:*:enterprise:*:*:* | ||
12.2.1.3.0CPE matchmatch criteria | cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:enterprise:*:*:* | ||
12.2.1.4.0CPE matchmatch criteria | cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.