Unauthorized Data Access in Oracle BI Publisher from Oracle Fusion Middleware
CVE-2021-2401
5.3MEDIUM
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 20 July 2021
What is CVE-2021-2401?
An unauthenticated attacker with network access can exploit a vulnerability in Oracle BI Publisher, which is part of Oracle Fusion Middleware, to gain unauthorized read access to specific data. This issue affects several supported versions of the software, potentially exposing sensitive information to attackers without requiring authentication.
Affected Version(s)
BI Publisher (formerly XML Publisher) 5.5.0.0.0
BI Publisher (formerly XML Publisher) 11.1.1.9.0
BI Publisher (formerly XML Publisher) 12.2.1.3.0