Oracle Bi Publisher vulnerabilities
36 known vulnerabilities affecting oracle/bi_publisher.
Total CVEs
36
CISA KEV
0
Public exploits
3
Exploited in wild
3
Severity breakdown
CRITICAL3HIGH20MEDIUM13
Vulnerabilities
Page 1 of 2
CVE-2019-11358P2MEDIUMCVSS 6.1ExploitedPoCv5.5.0.0.0v12.2.1.3.0+1 more2019-04-20
CVE-2019-11358 [MEDIUM] CWE-1321 CVE-2019-11358: jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(t
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
nvd
CVE-2019-2767P2HIGHCVSS 7.2ExploitedPoCv11.1.1.9.02019-07-23
CVE-2019-2767 [HIGH] CVE-2019-2767: Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (su
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The supported version that is affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher)
nvd
CVE-2017-5645P1CRITICALCVSS 9.8PoCv11.1.1.7.0v11.1.1.9.0+2 more2017-04-17
CVE-2017-5645 [CRITICAL] CWE-502 CVE-2017-5645: In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive s
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
nvd
CVE-2019-2768P2HIGHCVSS 7.5Exploitedv11.1.1.9.02019-07-23
CVE-2019-2768 [HIGH] CVE-2019-2768: Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (su
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The supported version that is affected is 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Successful attacks of this
nvd
CVE-2021-21346P2CRITICALCVSS 9.8v5.5.0.0.0v12.2.1.3.0+1 more2021-03-23
CVE-2021-21346 [CRITICAL] CWE-434 CVE-2021-21346: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security fr
nvd
CVE-2021-2400P2HIGHCVSS 7.5v5.5.0.0.0v11.1.1.9.0+2 more2021-07-21
CVE-2021-2400 [HIGH] CVE-2021-2400: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vul
nvd
CVE-2021-2396P2HIGHCVSS 8.8v5.5.0.0.0v11.1.1.9.0+2 more2021-07-21
CVE-2021-2396 [HIGH] CVE-2021-2396: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vuln
nvd
CVE-2021-2391P2HIGHCVSS 8.8v5.5.0.0.0v11.1.1.9.0+2 more2021-07-21
CVE-2021-2391 [HIGH] CVE-2021-2391: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Scheduler).
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Scheduler). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability ca
nvd
CVE-2021-2401P3MEDIUMCVSS 5.3v5.5.0.0.0v11.1.1.9.0+2 more2021-07-21
CVE-2021-2401 [MEDIUM] CWE-611 CVE-2021-2401: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks o
nvd
CVE-2024-21082P2CRITICALCVSS 9.8v7.0.0.0.0v12.2.1.4.02024-04-16
CVE-2024-21082 [CRITICAL] CWE-611 CVE-2024-21082: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Sup
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in tak
nvd
CVE-2021-2392P3HIGHCVSS 8.8v5.5.0.0.0v11.1.1.9.0+2 more2021-07-21
CVE-2021-2392 [HIGH] CVE-2021-2392: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publishe
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vuln
nvd
CVE-2024-21254P3HIGHCVSS 8.8v7.0.0.0.0v7.6.0.0.0+1 more2024-10-15
CVE-2024-21254 [HIGH] CWE-862 CVE-2024-21254: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Suppo
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in
nvd
CVE-2023-21846P3HIGHCVSS 8.8v5.9.0.0.0v6.4.0.0.0+1 more2023-01-18
CVE-2023-21846 [HIGH] CWE-284 CVE-2023-21846: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security).
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 5.9.0.0.0, 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle BI Publisher. Successful attacks of this vulnera
nvd
CVE-2023-21832P3HIGHCVSS 8.8v5.9.0.0.0v6.4.0.0.0+1 more2023-01-18
CVE-2023-21832 [HIGH] CWE-284 CVE-2023-21832: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security).
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 5.9.0.0.0, 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle BI Publisher. Successful attacks of this vulnera
nvd
CVE-2025-50060P3HIGHCVSS 8.1v7.6.0.0.0v8.2.0.0.0+1 more2025-07-15
CVE-2025-50060 [HIGH] CWE-284 CVE-2025-50060: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Suppo
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 7.6.0.0.0, 8.2.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in
nvd
CVE-2022-21346P3HIGHCVSS 7.5v5.5.0.0.0v12.2.1.3.0+1 more2022-01-19
CVE-2022-21346 [HIGH] CVE-2022-21346: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publishe
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability
nvd
CVE-2025-30724P3HIGHCVSS 7.5v7.6.0.0.0v12.2.1.4.02025-04-15
CVE-2025-30724 [HIGH] CWE-200 CVE-2025-30724: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Sup
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unautho
nvd
CVE-2022-21590P3HIGHCVSS 7.6v5.9.0.0.0v6.4.0.0.0+2 more2022-10-18
CVE-2022-21590 [HIGH] CVE-2022-21590: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Core Format
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Core Formatting API). Supported versions that are affected are 5.9.0.0, 6.4.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnera
nvd
CVE-2024-21195P3HIGHCVSS 7.6v7.0.0.0.0v7.6.0.0.0+1 more2024-10-15
CVE-2024-21195 [HIGH] CWE-284 CVE-2024-21195: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Layout Templates).
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Layout Templates). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can res
nvd
CVE-2024-21083P3HIGHCVSS 7.2v7.0.0.0.0v12.2.1.4.02024-04-16
CVE-2024-21083 [HIGH] CWE-863 CVE-2024-21083: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Script Engine). Su
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Script Engine). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeov
nvd
1 / 2Next →