S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2020-14864 Scanner

CVE-2020-14864 scanner - Improper Access Control vulnerability in Oracle Business Intelligence Enterprise Edition

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2020-14864
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Business Intelligence Enterprise Editionby Oracle Corporation
5.5.0.0.0
Updated Aug 21, 2026View on NVD →
Detail

Oracle Business Intelligence Enterprise Edition is a comprehensive business intelligence and analytics platform used by organizations to gather, analyze, and visualize data from a wide range of sources. It is designed to empower business users with insights needed to make data-driven decisions, enhance business agility, and accelerate growth. This product is widely deployed in various industries, including finance, retail, healthcare, and gaming.

Recently, a critical vulnerability, CVE-2020-14864, was discovered in the Oracle Business Intelligence Enterprise Edition product, specifically in its installation component. This vulnerability can be easily exploited by an unauthenticated attacker with network access via HTTP to gain unauthorized access to critical data or even obtain complete access to all Oracle Business Intelligence Enterprise Edition data accessible by exploiting this vulnerability.

If this vulnerability is exploited, it can lead to serious consequences, including unauthorized access to sensitive data, information leakage, loss of confidentiality, and compliance violations. This can result in massive financial losses for organizations, damaged reputation, and worse outcomes.

At s4e.io, we offer a state-of-the-art platform that enables organizations to identify, analyze, and prioritize vulnerabilities in their digital assets. Our pro feature offers advanced capabilities, such as threat intelligence and personalized alerts that enable organizations to stay ahead of evolving cyber threats. By leveraging s4e.io, organizations can be sure that their digital assets are secure, and their sensitive data is protected against cyberattacks.

 

REFERENCES

Solution Advice

Protecting against this vulnerability requires a vigilant approach and the implementation of appropriate measures. Here are some precautions that can be taken to minimize the risk of exploitation:

  • Ensure the installation of the latest security updates and patches provided by Oracle.
  • Limit the access rights of users and applications to only necessary privileges.
  • Disable web access to the Oracle Business Intelligence Enterprise Edition installation components if not required.
  • Implement network segmentation and firewalls to restrict access to critical systems and applications.
  • Use industry-standard security tools and practices, such as intrusion detection systems and vulnerability scanning.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-14864 scanner - Improper Access Control vulnerability in Oracle Business Intelligence Enterprise Edition S4E