Vulnerability in BI Publisher Product of Oracle Analytics
CVE-2023-22105

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 October 2023

Summary

The BI Publisher component of Oracle Analytics is vulnerable to exploitation by low privileged attackers with network access via HTTP. This vulnerability is easily exploitable and requires human interaction from an individual other than the attacker. Compromise of BI Publisher can lead to unauthorized update, insert, or delete operations to accessible data, as well as potential unauthorized reading of sensitive data. Although the vulnerability exists primarily within BI Publisher, the implications of successful attacks may extend to other connected products, resulting in significant scope changes and data integrity concerns.

Affected Version(s)

BI Publisher (formerly XML Publisher) 6.4.0.0.0

BI Publisher (formerly XML Publisher) 7.0.0.0.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.