QID 730390
QID 730390: Oracle Business Intelligence Enterprise Edition Local File Inclusion (LFI) Vulnerability (CPUOCT2020)
Oracle Fusion Middleware is the digital business platform for the enterprise and the cloud.
A Directory Traversal vulnerability has been discovered in the 'getPreviewImage' function of Oracle Business Intelligence Enterprise Edition. The 'getPreviewImage' function is used to get a preview image of a previously uploaded theme logo. By manipulating the 'previewFilePath' URL parameter an attacker with access to the administration interface is able to read arbitrary system files.
Affected Versions:
Oracle Fusion Middleware 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable software by sending a crafted payload to the server.
Successful attacks of this vulnerability may allow a remote attacker to read sensitive files on the server.
- CPUOCT2020 -
www.oracle.com/security-alerts/cpuoct2020.html
CVEs related to QID 730390
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cpuoct2020 |
|