Description
Oracle Business Intelligence is vulnerable to deserialization attacks. An attacker could exploit this vulnerability using specially-crafted serialized data to execute arbitrary code on the system or to perform denial of service attack.
Remediation
Upgrade to the latest version of Oracle Business Intelligence
References
Oracle Critical Patch Update Advisory - April 2020
Java Unmarshaller Security - Turning your data into code execution