Vulnerability in Oracle Business Intelligence Enterprise Edition by Oracle
CVE-2023-21965

5.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 April 2023

Summary

A vulnerability exists in Oracle's Business Intelligence Enterprise Edition that allows low privileged attackers with HTTP network access to exploit the system. The attack requires human interaction from a non-attacker party, enabling unauthorized access to critical data. Consequently, this could lead to complete access to sensitive information within the Oracle Business Intelligence framework.

Affected Version(s)

Business Intelligence Enterprise Edition 6.4.0.0.0

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.