Description
ReportTemplateService service in Oracle Business Intelligence has an XXE vulnerability. This vulnerability allows an attacker to send crafted requests to a web application for extraction of secrets from the file system, server-side request forgery or denial-of-service attacks.
Remediation
Upgrade to the latest version of Oracle Business Intelligence. This issue was fixed in Oracle Critical Patch Update - April 2019
References
Related Vulnerabilities
MySQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-10379)
MySQL NULL Pointer Dereference Vulnerability (CVE-2021-22570)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1447)
Oracle HTTP Server CVE-2007-0280 Vulnerability (CVE-2007-0280)
Apache read beyond bounds via ap_rwrite() Vulnerability (CVE-2022-28614)