Title: Oracle BI Publisher Administration Subcomponent XML External Entity (XXE) Data Parsing Arbitrary File Disclosure
Info
Disclosure
Oct 16, 2012
Discovery
Unknown
Dates
Exploit
Nov 28, 2012
Solution
Oct 16, 2012
Description
The Administration Subcomponent of Oracle BI Publisher contains an XXE (Xml eXternal Entity) injection flaw that is triggered during the parsing of XML data. The issue is due to an incorrectly configured XML parser accepting XML external entities from an untrusted source. By sending specially crafted XML data, a remote attacker can gain access to arbitrary files.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Patch / RCS
Exploit:
Exploit Public
Disclosure:
Vendor Verified,
Coordinated Disclosure
OSVDB:
Authentication Required,
Web Related
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, Oracle has released a patch to address this vulnerability. Check the vendor advisory in the references section.