Vulnerability in Oracle Business Intelligence Enterprise Edition by Oracle
CVE-2023-21891

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 January 2023

Summary

The vulnerability in Oracle Business Intelligence Enterprise Edition allows low privileged attackers with network access via HTTP to compromise the system. Exploitation requires human interaction, which can lead to unauthorized data manipulation, including updates, inserts, and deletions. This breach may extend its impact beyond the initial application, emphasizing the need for robust security measures to protect sensitive data within affected versions.

Affected Version(s)

Business Intelligence Enterprise Edition 5.9.0.0.0

Business Intelligence Enterprise Edition 6.4.0.0.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.