Unauthorized Access Vulnerability in Oracle BI Publisher by Oracle
CVE-2021-2062
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 20 January 2021
What is CVE-2021-2062?
An exploitable vulnerability exists in Oracle BI Publisher, part of Oracle Fusion Middleware’s web server component, which allows an attacker with low privileges to compromise the product. Successful exploitation requires human interaction from a victim but can lead to unauthorized access to sensitive data and potentially allow attackers to update, insert or delete data within the affected Oracle BI Publisher instances. This vulnerability can have far-reaching impacts, affecting additional connected products and services.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
BI Publisher (formerly XML Publisher) 5.5.0.0.0
BI Publisher (formerly XML Publisher) 11.1.1.9.0
BI Publisher (formerly XML Publisher) 12.2.1.3.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved