Description
ReportTemplateService service in Oracle Business Intelligence has an XXE vulnerability. This vulnerability allows an attacker to send crafted requests to a web application for extraction of secrets from the file system, server-side request forgery or denial-of-service attacks.
Remediation
Upgrade to the latest version of Oracle Business Intelligence. This issue was fixed in Oracle Critical Patch Update - April 2019
References
Related Vulnerabilities
Moodle Insufficient Verification of Data Authenticity Vulnerability (CVE-2020-1755)
Moodle Improper Authentication Vulnerability (CVE-2022-0985)
Zend Framework local file disclosure via XXE injection
MySQL CVE-2012-1757 Vulnerability (CVE-2012-1757)
Oracle HTTP Server Use After Free Vulnerability (CVE-2019-10082)