This video demonstrates how an unauthenticated attacker could execute commands on affected versions of the Oracle Business Intelligence Virtual Appliance. This vulnerability resides in "BIRemotingServlet", which listens on port TCP port 7780 and does not require any authentication.
For full details on the vulnerability, see the blog at https://www.zerodayinitiative.com/blo...