Web Server Vulnerability in Oracle Analytics BI Publisher
CVE-2024-20987
5.4MEDIUM
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 16 January 2024
What is CVE-2024-20987?
A vulnerability exists in the Oracle BI Publisher component of Oracle Analytics, which may allow a low-privilege attacker with network access via HTTP to compromise the system. Successful exploitation requires user interaction from someone other than the attacker, and while it primarily affects Oracle BI Publisher, the consequences can extend to additional products. Attackers could gain unauthorized access to update, insert, or delete data within Oracle BI Publisher and read certain accessible data unauthorizedly. This vulnerability demonstrates the need for enhanced security measures and awareness of potential attacks against web server components.
Affected Version(s)
BI Publisher (formerly XML Publisher) 12.2.1.4.0