Oracle Business Intelligence Enterprise Edition Path Transversal
Oracle · Intelligence Enterprise Edition
Date added (CISA)
2022-01-18
Remediation due
2022-07-18
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file.