CVE-2020-14864
악용 확인 Oracle Business Intelligence Enterprise Edition Path Transversal
악용 여부
악용 확인
심각도 (발행처 발표값)
높음7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
악용 확률 (EPSS)
97.2%
한국어 공식 권고
CISA 원문
Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file.— CISA KEV · shortDescription 원문
Apply updates per vendor instructions.— CISA KEV · requiredAction 원문
취약점 설명 (NVD 원문)
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
CWE-22
악용 확률 변화
| 기준일 | 확률 | 백분위 |
|---|---|---|
| 2026-09-06 | 97.23% | 99.9% |
| 2026-09-05 | 97.23% | 99.9% |
| 2026-09-04 | 97.23% | 99.9% |