Vulnerability in Oracle Business Intelligence Enterprise Edition by Oracle
CVE-2023-21965
5.7MEDIUM
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 18 April 2023
What is CVE-2023-21965?
A vulnerability exists in Oracle's Business Intelligence Enterprise Edition that allows low privileged attackers with HTTP network access to exploit the system. The attack requires human interaction from a non-attacker party, enabling unauthorized access to critical data. Consequently, this could lead to complete access to sensitive information within the Oracle Business Intelligence framework.
Affected Version(s)
Business Intelligence Enterprise Edition 6.4.0.0.0