CVE-2019-2616
published 2019-04-23CVE-2019-2616: Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that…
PriorityP188high7.2CVSS 3.1
AVNACLPRNUINSCCLILAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
92.18%
99.8th percentile
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). While the vulnerability is in BI Publisher (formerly XML Publisher), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of BI Publisher (formerly XML Publisher) accessible data as well as unauthorized read access to a subset of BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | business_intelligence_publisher | — | — |
| oracle | business_intelligence_publisher | — | — |
| oracle | business_intelligence_publisher | — | — |
| oracle_corporation | bi_publisher | — | — |
| oracle_corporation | bi_publisher | — | — |
| oracle_corporation | bi_publisher | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unauthenticated HTTP POST requests to /xmlpserver/ReportTemplateService.xls with a Content-Type of 'text/xml' — this is the specific endpoint and method used in the XXE exploit. ↗
- →Detect outbound HTTP interactions triggered from the BI Publisher server (SSRF/OOB XXE) — the Nuclei template confirms exploitation via an out-of-band HTTP callback (interactsh_protocol = 'http'). ↗
- →Flag unauthenticated POST requests carrying XML payloads to the ReportTemplateService endpoint; the vulnerability requires no credentials (PR:N, UI:N) and is network-accessible over HTTP. ↗
- →Open-source reporting attributes this vulnerability to authentication bypass — alert on any access to BI Publisher administrative or reporting endpoints without a valid session token. ↗
- ·The exploit targets three specific versions of Oracle BI Publisher; detection rules should be scoped to environments running 11.1.1.9.0, 12.2.1.3.0, or 12.2.1.4.0 to reduce false positives. ↗
- ·The vulnerability has a very high EPSS score (0.93992, 99.892nd percentile), indicating active exploitation in the wild — prioritise detection and patching accordingly. ↗
- ·Scope of impact extends beyond the directly attacked product (S:C in CVSS vector), meaning successful exploitation can affect other components in the same environment — broaden monitoring to adjacent systems. ↗
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vulncheck7.2HIGH
cisa7.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8j2r-c64f-x52g: Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security)
ghsa_unreviewed·2022-05-24
CVE-2019-2616 [HIGH] GHSA-8j2r-c64f-x52g: Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security)
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). While the vulnerability is in BI Publisher (formerly XML Publisher), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of BI Publisher (formerly XML Publisher) accessible data as well as unauthorized read access to a subset of BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 7.2 (Confidentiality an
VulnCheck
Oracle BI Publisher Unauthorized Access Vulnerability
vulncheck·2019·CVSS 7.2
CVE-2019-2616 [HIGH] Oracle BI Publisher Unauthorized Access Vulnerability
Oracle BI Publisher Unauthorized Access Vulnerability
Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass.
Affected: Oracle BI Publisher
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2024-01-04&host_type=src&vulnerability=cve-2019-2616; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2024-01-22&host_type=src&vulnerability=cve-2019-2616; https://dashboard.shadowserver.org/statistics/honeypot/vulnera
CISA
Oracle BI Publisher Unauthorized Access Vulnerability
cisa·2022-03-25·CVSS 7.2
CVE-2019-2616 [HIGH] Oracle BI Publisher Unauthorized Access Vulnerability
Vulnerability: Oracle BI Publisher Unauthorized Access Vulnerability
Affected: Oracle BI Publisher (Formerly XML Publisher)
Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-2616
Remediation Due Date: 2022-04-15
No detection rules found.
Exploit-DB
Oracle Business Intelligence / XML Publisher 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - XML External Entity Injection
exploitdb·2019-04-19·CVSS 7.2
CVE-2019-2616 [HIGH] Oracle Business Intelligence / XML Publisher 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - XML External Entity Injection
Oracle Business Intelligence / XML Publisher 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - XML External Entity Injection
---
# Exploit Title: XXE in Oracle Business Intelligence and XML Publisher
# Date: 16.04.19
# Exploit Author: @vah_13
# Vendor Homepage: http://oracle.com
# Software Link:
https://www.oracle.com/technetwork/middleware/bi-enterprise-edition/downloads/index.html
# Version: 11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0
# Tested on: Windows
# CVE : CVE-2019-2616 (7.2/10)
PoC:
POST /xmlpserver/ReportTemplateService.xls HTTP/1.1
Host: host
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101
Firefox/62.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Content-Length: 76
Content-Type: text/xml; charset=UTF-8
">
Nuclei
Oracle Business Intelligence/XML Publisher - XML External Entity Injection
nuclei·CVSS 7.2
CVE-2019-2616 [HIGH] Oracle Business Intelligence/XML Publisher - XML External Entity Injection
Oracle Business Intelligence/XML Publisher - XML External Entity Injection
Oracle Business Intelligence and XML Publisher 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 are vulnerable to an XML external entity injection attack.
Template:
id: CVE-2019-2616
info:
name: Oracle Business Intelligence/XML Publisher - XML External Entity Injection
author: pdteam
severity: high
description: Oracle Business Intelligence and XML Publisher 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 are vulnerable to an XML external entity injection attack.
impact: |
Successful exploitation of this vulnerability could allow an attacker to read arbitrary files on the server or conduct server-side request forgery (SSRF) attacks.
remediation: |
Apply the necessary patches or updates provided by Oracle to fix this vulnerability.
refe
Unit42
Attackers Are Taking Advantage of the Open-Source Service Interactsh for Malicious Purposes
blogs_unit42·2021-10-14
Attackers Are Taking Advantage of the Open-Source Service Interactsh for Malicious Purposes
## Executive Summary
Recently, Unit 42 has observed active exploits related to an open-source service called Interactsh. This tool can generate specific domain names to help its users test whether an exploit is successful. It can be used by researchers – but also by attackers – to validate vulnerabilities via real-time monitoring on the trace path for the domain. Researchers creating a proof of concept (PoC) for an exploit can insert Interactsh to check whether the PoC is working, but the service could also be used by attackers who want to be sure an exploit is working.
This blog will first introduce the Interactsh tool and how researchers or attackers can leverage it to perform vulnerability validation. We then describe some of the many exploits in the wild leveraging this tool, and we
Unit42
Attackers Are Taking Advantage of the Open-Source Service Interactsh for Malicious Purposes
blogs_unit42·2021-10-14
Attackers Are Taking Advantage of the Open-Source Service Interactsh for Malicious Purposes
Threat Research Center
Threat Research
Cybercrime
## Attackers Are Taking Advantage of the Open-Source Service Interactsh for Malicious Purposes
Yue Guan
Jin Chen
Leo Olson
Wayne Xin
Daiping Liu
Published: October 14, 2021
Cybercrime
Threat Research
Attack analysis
Exploit
Exploit in the wild
Interactsh
## Executive Summary
Recently, Unit 42 has observed active exploits related to an open-source service called Interactsh . This tool can generate specific domain names to help its users test whether an exploit is successful. It can be used by researchers – but also by attackers – to validate vulnerabilities via real-time monitoring on the trace path for the domain. Researchers creating a proof of concept (PoC) for an exploit can insert Interactsh to check whether the PoC
2019-04-23
Published
2022-03-25
Added to CISA KEV
Exploited in the wild