Vulnerability in Oracle BI Publisher of Oracle Analytics
CVE-2024-21082

9.8CRITICAL

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 April 2024

Summary

A vulnerability exists in Oracle BI Publisher, a component of Oracle Analytics, affecting versions 7.0.0.0.0 and 12.2.1.4.0. This vulnerability can be easily exploited by an unauthenticated attacker with network access through HTTP. Successful exploitation may allow for a complete takeover of the Oracle BI Publisher platform. The implications of this vulnerability significantly affect confidentiality, integrity, and availability, emphasizing the need for immediate attention and remediation in affected systems.

Affected Version(s)

BI Publisher (formerly XML Publisher) 7.0.0.0.0

BI Publisher (formerly XML Publisher) 12.2.1.4.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.