Skip to main content

CVE-2020-14864

7.5
HIGHCVSS v3.1 Base Score
94.02%
HIGH RiskEPSS (100th percentile)
KEV

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Published: 10/21/2020
Modified: 10/27/2025
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Oracle Business Intelligence Enterprise Edition Path Transversal

Vendor / Product:

Oracle Intelligence Enterprise Edition

Required Action:

Apply updates per vendor instructions.

Due Date: 7/18/2022(OVERDUE)
Added to KEV:

1/18/2022

Notes:

https://nvd.nist.gov/vuln/detail/CVE-2020-14864

Vulnerability Summary

CVSS v3 Score

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v2 Score

7.8

AV:N/AC:L/Au:N/C:C/I:N/A:N

EPSS Score (Exploitation Probability)

94.02%HIGH Exploitation Risk
100th percentile

This vulnerability has a 94.02% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-22)

CVE-2026-7594HIGH 7.3

A vulnerability was detected in Flux159 mcp-game-asset-gen 0.1.0. Affected is the function image_to_3d_async of the file src/index.ts of the component MCP Interface. The manipulation of the argument statusFile results in path traversal. The attack can be executed remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

5/1/2026
CVE-2026-1056CRITICAL 9.8

The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'generate_user_dirpath' function in all versions up to, and including, 12.0.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

1/28/2026
CVE-2026-22249HIGH 7.1

Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulnerable to Arbitrary File Write via Zip Import Feature (ZipSlip). In apps/server/src/integrations/import/utils/file.utils.ts, there are no validation on filename. This vulnerability is fixed in 0.24.0.

1/15/2026
CVE-2025-67004MEDIUM 6.5

** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directories back after back. It can Disclosure the source code or any other confidential information if weaponize accordingly. NOTE: A community member states that this is not a CouchCMS vulnerability and that if /\<file> is accessible it is a web-server configuration issue.

1/9/2026
CVE-2025-66744HIGH 7.5

In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to path traversal, allowing unauthorized access to sensitive information within the system

1/9/2026

Similar SeverityHIGH