OSVDB ID: 86390

Title: Oracle BI Publisher Administration Subcomponent XML External Entity (XXE) Data Parsing Arbitrary File Disclosure

Info

Disclosure

Oct 16, 2012

Discovery

Unknown

Dates

Exploit

Nov 28, 2012

Solution

Oct 16, 2012

Description

The Administration Subcomponent of Oracle BI Publisher contains an XXE (Xml eXternal Entity) injection flaw that is triggered during the parsing of XML data. The issue is due to an incorrectly configured XML parser accepting XML external entities from an untrusted source. By sending specially crafted XML data, a remote attacker can gain access to arbitrary files.

Classification

Location: Remote / Network Access
Attack Type: Information Disclosure
Impact: Loss of Confidentiality
Solution: Patch / RCS
Exploit: Exploit Public
Disclosure: Vendor Verified, Coordinated Disclosure
OSVDB: Authentication Required, Web Related

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Oracle has released a patch to address this vulnerability. Check the vendor advisory in the references section.

Products

Oracle Corporation

BI Publisher

10.3.4.2
11.1.1.5.0
11.1.1.6.0
11.1.1.6.2

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/86390