Oracle Analytics Cloud and Server

Welcome to the Oracle Analytics Community: Please complete your User Profile and upload your Profile Picture

directory traversal attacks in OBIEE 12.2.1.2

Question
1
Views
0
Comments
3265587
3265587 Rank 1 - Community Starter

we have upgraded our OBIEE 11g instance to 12.2.1.2. every thing completed successfully. Now we are above to go live. Our security personals scan OBIEE 12c with Acunetix Security Audit. And they have found following

Affected items :  /analytics/res/v-878RdqqH*RU

Alert group : Server directory traversal

Severity  High

Description :  This script is possibly vulnerable to directory traversal attacks. Directory Traversal is a vulnerability which allows attackers to access restricted                                  directories and read files outside of the web server's root directory.

Recommendations : Your script should filter metacharacters from user input.

Alert variants : This file was found using the pattern /analytics/res/v-878RdqqH*RU/../WEB-INF/web.xml?.

                         Original directory: /analytics/res/v-878RdqqH*RU

                         Pattern found:

I have search above Path in the server. there is no such a path.

Please help us to over come the issue