Vulnerability in Oracle Business Intelligence Enterprise Edition by Oracle
CVE-2023-22082

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 October 2023

Summary

An exploitable vulnerability in Oracle Business Intelligence Enterprise Edition's Pod Admin component allows an attacker with low privileges and network access to compromise sensitive data. This vulnerability necessitates human interaction to initiate an attack but can lead to unauthorized updates, inserts, or deletions of data. Additionally, there is potential for unauthorized read access to certain data subsets, jeopardizing data privacy and integrity across Oracle's analytics services. The implications of this vulnerability are substantial, potentially affecting multiple products within the ecosystem.

Affected Version(s)

Business Intelligence Enterprise Edition 6.4.0.0.0

Business Intelligence Enterprise Edition 7.0.0.0.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.