January 18, 2022 · Applied Cybernetics Group
CVE-2020-14864 — Oracle Intelligence Enterprise Edition
Oracle Business Intelligence Enterprise Edition Path Transversal
- Added to KEV
2022-01-18- Federal due date
2022-07-18- Vendor
- Oracle
- Product
- Intelligence Enterprise Edition
- EPSS
- 99.9th percentile (score 0.940, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2020-14864
CISA short description
Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file.
Required action
Apply updates per vendor instructions.