← Vulnerability feed

Vulnerability record · CVE-2020-14864 · published 21 October 2020

CVE-2020-14864: Oracle Business Intelligence Enterprise Edition path traversal allows unauthenticated data access

Oracle · Business Intelligence

Oracle Business Intelligence Enterprise Edition contains a path traversal flaw in its Installation component affecting versions 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. An unauthenticated network attacker can exploit it to read files outside the intended directory, exposing critical data. It is listed in CISA KEV, so it is being exploited in the wild.

7.5 CVSS 3.1 High CISA KEV since 18 Jan 2022 EPSS 97% · top 0.1% CWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 7.8
97%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with a near-maximum EPSS score and allows unauthenticated network attackers to read critical data.

What it is

Oracle Business Intelligence Enterprise Edition contains a path traversal flaw in its Installation component affecting versions 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. An unauthenticated network attacker can exploit it to read files outside the intended directory, exposing critical data. It is listed in CISA KEV, so it is being exploited in the wild.

Impact

An attacker gains unauthorized read access to critical data or all data accessible to the Oracle BI Enterprise Edition deployment. No write or code execution is described in the record.

Attack surface

Reachable over the network via HTTP with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The flaw sits in the Installation component and is a path traversal (CWE-22), consistent with the referenced LFI advisory.

Exploitation

CISA added it to KEV on 2022-01-18 with a 2022-07-18 remediation due date, and EPSS is 0.97233 (99.891st percentile), indicating active exploitation and very high likelihood. No ransomware campaign use is recorded.

What to do

  • Apply the Oracle October 2020 Critical Patch Update for BI Enterprise Edition versions 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0.
  • If patching cannot be done immediately, restrict network access to the BI installation endpoints to trusted hosts only.
  • Place the BI deployment behind an authenticated reverse proxy or WAF rule that blocks traversal sequences in request paths.
  • Review file system permissions so the BI service account cannot read sensitive files outside its required directories.
  • Confirm remediation against the CISA KEV due date and track the asset as known-exploited until patched.

Detection

  • Search web and proxy logs for encoded traversal patterns such as ../, %2e%2e%2f and %252e%252e%252f in requests to BI endpoints.
  • Alert on HTTP requests to BI installation paths from unauthenticated or unexpected source IPs.
  • Monitor the BI service account for reads of files outside its normal directories using file integrity or audit tooling.
  • Correlate outbound data transfers from BI hosts with unusual request volumes to detect data exfiltration.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-14864 to the Known Exploited Vulnerabilities catalog on 18 January 2022 as "Oracle Business Intelligence Enterprise Edition Path Transversal". Required action: Apply updates per vendor instructions. Federal deadline 18 July 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-14864 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-17530Apache Struts forced OGNL evaluation enables remote code executionApache Struts 2.0.0 through 2.5.25 performs forced OGNL evaluation on raw user input placed in tag attributes, allowing expression language injection…KEVEPSS 96%analysed6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed9.8CVE-2022-23305Log4j 1.x JDBCAppender SQL injection via logged inputThe JDBCAppender in Log4j 1.2.x builds SQL statements from configuration parameters and PatternLayout converters, so logged values such as the %m mes…EPSS 67%analysed9.8CVE-2021-2456Oracle Business Intelligence Enterprise Edition unauthenticated takeoverOracle Business Intelligence Enterprise Edition 12.2.1.4.0 contains a flaw in the Analytics Web General component that is reachable over HTTP without…EPSS 81%analysed9.8CVE-2020-9480Apache spark missing authentication for critical function vulnerabilityIn Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shar…EPSS 29%9.8CVE-2020-2950Oracle Business Intelligence Enterprise Edition unauthenticated takeoverOracle Business Intelligence Enterprise Edition (Analytics Web General) contains an easily exploitable flaw affecting versions 5.5.0.0.0, 11.1.1.9.0,…EPSS 71%analysed9.8CVE-2018-8013Apache batik deserialization of untrusted data vulnerabilityIn Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name w…EPSS 19%8.8CVE-2026-71055Oracle business intelligence improper access control vulnerabilityVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported versio…EPSS 0.43%

Source: NIST National Vulnerability Database (record CVE-2020-14864), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.