Vulnerability record · CVE-2020-14864 · published 21 October 2020
CVE-2020-14864: Oracle Business Intelligence Enterprise Edition path traversal allows unauthenticated data access
Oracle · Business Intelligence
Oracle Business Intelligence Enterprise Edition contains a path traversal flaw in its Installation component affecting versions 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. An unauthenticated network attacker can exploit it to read files outside the intended directory, exposing critical data. It is listed in CISA KEV, so it is being exploited in the wild.
Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityIt is in CISA KEV with a near-maximum EPSS score and allows unauthenticated network attackers to read critical data.
What it is
Oracle Business Intelligence Enterprise Edition contains a path traversal flaw in its Installation component affecting versions 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. An unauthenticated network attacker can exploit it to read files outside the intended directory, exposing critical data. It is listed in CISA KEV, so it is being exploited in the wild.
Impact
An attacker gains unauthorized read access to critical data or all data accessible to the Oracle BI Enterprise Edition deployment. No write or code execution is described in the record.
Attack surface
Reachable over the network via HTTP with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The flaw sits in the Installation component and is a path traversal (CWE-22), consistent with the referenced LFI advisory.
Exploitation
CISA added it to KEV on 2022-01-18 with a 2022-07-18 remediation due date, and EPSS is 0.97233 (99.891st percentile), indicating active exploitation and very high likelihood. No ransomware campaign use is recorded.
What to do
- Apply the Oracle October 2020 Critical Patch Update for BI Enterprise Edition versions 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0.
- If patching cannot be done immediately, restrict network access to the BI installation endpoints to trusted hosts only.
- Place the BI deployment behind an authenticated reverse proxy or WAF rule that blocks traversal sequences in request paths.
- Review file system permissions so the BI service account cannot read sensitive files outside its required directories.
- Confirm remediation against the CISA KEV due date and track the asset as known-exploited until patched.
Detection
- Search web and proxy logs for encoded traversal patterns such as ../, %2e%2e%2f and %252e%252e%252f in requests to BI endpoints.
- Alert on HTTP requests to BI installation paths from unauthenticated or unexpected source IPs.
- Monitor the BI service account for reads of files outside its normal directories using file integrity or audit tooling.
- Correlate outbound data transfers from BI hosts with unusual request volumes to detect data exfiltration.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-14864 to the Known Exploited Vulnerabilities catalog on 18 January 2022 as "Oracle Business Intelligence Enterprise Edition Path Transversal". Required action: Apply updates per vendor instructions. Federal deadline 18 July 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/159748/Oracle-Business-Intelligence-Enterprise-Edition-5.5.0.0.0-12.2.1.3.0-12.2.1. | Third Party AdvisoryVDB Entry |
| https://www.oracle.com/security-alerts/cpuoct2020.html | Vendor Advisory |
| http://packetstormsecurity.com/files/159748/Oracle-Business-Intelligence-Enterprise-Edition-5.5.0.0.0-12.2.1.3.0-12.2.1. | Third Party AdvisoryVDB Entry |
| https://www.oracle.com/security-alerts/cpuoct2020.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-14864 | US Government Resource |
Track CVE-2020-14864 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-14864), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.