漏洞描述
Oracle Business Intelligence versions 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0 are vulnerable to path traversal in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security).
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.oracle.comhttp://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2019-2588↗github.comhttps://github.com/ARPSyndicate/kenzer-templates↗github.comhttps://github.com/Elsfa7-110/kenzer-templates↗github.comhttps://github.com/lnick2023/nicenice↗