Unauthenticated Input Vulnerability in Oracle Business Intelligence Enterprise Edition
CVE-2022-21448

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 April 2022

Summary

A vulnerability exists in Oracle Business Intelligence Enterprise Edition that allows unauthenticated attackers to exploit the system through HTTP. This exploit can lead to unauthorized updates, inserts, or deletions of accessible data. The vulnerability specifically affects version 5.9.0.0.0 and can have repercussions on other interconnected products within the Oracle Fusion Middleware. Successful exploitation necessitates human interaction from a non-attacker, making it an insidious threat that could compromise data confidentiality and integrity, impacting the overall security posture of organizations relying on this platform.

Affected Version(s)

Business Intelligence Enterprise Edition 5.9.0.0.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.