Web Server Vulnerability in Oracle BI Publisher by Oracle
CVE-2025-50060

8.1HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 July 2025

What is CVE-2025-50060?

An exploitable vulnerability exists in the Oracle BI Publisher component of Oracle Analytics. This weakness can be targeted by low-privileged attackers with network access via HTTP, potentially allowing them to create, delete, or modify critical data or even gain complete access to all data accessible within Oracle BI Publisher. This could lead to serious breaches of confidentiality and integrity, threatening the security of sensitive information.

Affected Version(s)

Oracle BI Publisher 7.6.0.0.0

Oracle BI Publisher 8.2.0.0.0

Oracle BI Publisher 12.2.1.4.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.