Vulnerability in Oracle BI Publisher of Oracle Analytics
CVE-2024-21082
9.8CRITICAL
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 16 April 2024
Summary
A vulnerability exists in Oracle BI Publisher, a component of Oracle Analytics, affecting versions 7.0.0.0.0 and 12.2.1.4.0. This vulnerability can be easily exploited by an unauthenticated attacker with network access through HTTP. Successful exploitation may allow for a complete takeover of the Oracle BI Publisher platform. The implications of this vulnerability significantly affect confidentiality, integrity, and availability, emphasizing the need for immediate attention and remediation in affected systems.
Affected Version(s)
BI Publisher (formerly XML Publisher) 7.0.0.0.0
BI Publisher (formerly XML Publisher) 12.2.1.4.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published