Unauthenticated Access Vulnerability in Oracle Business Intelligence Enterprise Edition
CVE-2020-14690

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 July 2020

Summary

A vulnerability exists in Oracle Business Intelligence Enterprise Edition that enables unauthenticated attackers with network access to exploit the system through HTTP. While this vulnerability predominantly affects the Oracle Business Intelligence Enterprise Edition, successful exploitation can lead to significant repercussions for associated systems and applications. This vulnerability requires human interaction from a third party for the attack to succeed, potentially leading to unauthorized access to sensitive data, as well as the ability to perform unauthorized updates, inserts, or deletions on data within the Oracle Business Intelligence framework.

Affected Version(s)

Oracle Business Intelligence Enterprise Edition 5.5.0.0.0

Oracle Business Intelligence Enterprise Edition 11.1.1.9.0

Oracle Business Intelligence Enterprise Edition 12.2.1.3.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.