Security Vulnerability in Oracle BI Publisher of Oracle Analytics
CVE-2023-21970
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 18 April 2023
What is CVE-2023-21970?
A vulnerability exists in the Oracle BI Publisher component of Oracle Analytics that can be exploited by a low privileged attacker with network access via HTTP. This vulnerability allows unauthorized access to sensitive data and could lead to complete access to all data accessible through Oracle BI Publisher. Successful exploitation requires human interaction from an individual other than the attacker, raising concerns about data confidentiality and access control. Organizations must take precautionary measures to mitigate such risks and protect sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
BI Publisher (formerly XML Publisher) 6.4.0.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved