Security Vulnerability in Oracle BI Publisher of Oracle Analytics
CVE-2023-21970

5.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 April 2023

Summary

A vulnerability exists in the Oracle BI Publisher component of Oracle Analytics that can be exploited by a low privileged attacker with network access via HTTP. This vulnerability allows unauthorized access to sensitive data and could lead to complete access to all data accessible through Oracle BI Publisher. Successful exploitation requires human interaction from an individual other than the attacker, raising concerns about data confidentiality and access control. Organizations must take precautionary measures to mitigate such risks and protect sensitive information.

Affected Version(s)

BI Publisher (formerly XML Publisher) 6.4.0.0.0

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.