Unauthorized Data Access Vulnerability in Oracle Fusion Middleware BI Publisher
CVE-2020-14880
8.5HIGH
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 21 October 2020
Summary
An exploit in the BI Publisher component of Oracle Fusion Middleware allows attackers with low privileges and network access to compromise sensitive data. Although primarily affecting BI Publisher, successful exploitation could lead to unauthorized access to crucial data across other linked products. This vulnerability enables attackers to update, insert, or delete information, significantly jeopardizing data integrity and confidentiality.
Affected Version(s)
BI Publisher (formerly XML Publisher) 5.5.0.0.0
BI Publisher (formerly XML Publisher) 11.1.1.9.0
BI Publisher (formerly XML Publisher) 12.2.1.3.0
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved