Vulnerability in BI Publisher Product of Oracle Analytics
CVE-2023-22105
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 17 October 2023
Summary
The BI Publisher component of Oracle Analytics is vulnerable to exploitation by low privileged attackers with network access via HTTP. This vulnerability is easily exploitable and requires human interaction from an individual other than the attacker. Compromise of BI Publisher can lead to unauthorized update, insert, or delete operations to accessible data, as well as potential unauthorized reading of sensitive data. Although the vulnerability exists primarily within BI Publisher, the implications of successful attacks may extend to other connected products, resulting in significant scope changes and data integrity concerns.
Affected Version(s)
BI Publisher (formerly XML Publisher) 6.4.0.0.0
BI Publisher (formerly XML Publisher) 7.0.0.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved