Unauthorized Access Vulnerability in Oracle Business Intelligence Enterprise Edition
CVE-2020-14609
8.6HIGH
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 15 July 2020
What is CVE-2020-14609?
An improper access control vulnerability in Oracle Business Intelligence Enterprise Edition allows an unauthenticated attacker with HTTP network access to exploit the system. Affected versions enable remote attackers to obtain unauthorized access to sensitive data, perform unapproved updates, inserts, or deletions of data, and potentially lead to a partial denial of service. Organizations utilizing these versions should take immediate action to secure their environments and patch vulnerable deployments.
Affected Version(s)
Oracle Business Intelligence Enterprise Edition 5.5.0.0.0
Oracle Business Intelligence Enterprise Edition 11.1.1.9.0
Oracle Business Intelligence Enterprise Edition 12.2.1.3.0