Vulnerability in Oracle Business Intelligence Enterprise Edition by Oracle
CVE-2023-21965
5.7MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 18 April 2023
Summary
A vulnerability exists in Oracle's Business Intelligence Enterprise Edition that allows low privileged attackers with HTTP network access to exploit the system. The attack requires human interaction from a non-attacker party, enabling unauthorized access to critical data. Consequently, this could lead to complete access to sensitive information within the Oracle Business Intelligence framework.
Affected Version(s)
Business Intelligence Enterprise Edition 6.4.0.0.0
References
CVSS V3.1
Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved