The Administration Subcomponent of Oracle BI Publisher contains an XXE (Xml eXternal Entity) injection flaw that is triggered during the parsing of XML data. The issue is due to an incorrectly configured XML parser accepting XML external entities from an untrusted source. By sending specially crafted XML data, a remote attacker can gain access to arbitrary files.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Patch / RCS
Exploit:
Exploit Public
Disclosure:
Vendor Verified,
Coordinated Disclosure
OSVDB:
Authentication Required,
Web Related
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, Oracle has released a patch to address this vulnerability. Check the vendor advisory in the references section.