Vulnerability in Oracle Business Intelligence Enterprise Edition by Oracle
CVE-2023-21891
5.4MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 18 January 2023
Summary
The vulnerability in Oracle Business Intelligence Enterprise Edition allows low privileged attackers with network access via HTTP to compromise the system. Exploitation requires human interaction, which can lead to unauthorized data manipulation, including updates, inserts, and deletions. This breach may extend its impact beyond the initial application, emphasizing the need for robust security measures to protect sensitive data within affected versions.
Affected Version(s)
Business Intelligence Enterprise Edition 5.9.0.0.0
Business Intelligence Enterprise Edition 6.4.0.0.0
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved