cbcvebase.

Oracle Bi Publisher vulnerabilities

36 known vulnerabilities affecting oracle/bi_publisher.

Total CVEs
36
CISA KEV
0
Public exploits
3
Exploited in wild
3
Severity breakdown
CRITICAL3HIGH20MEDIUM13

Vulnerabilities

Page 2 of 2
CVE-2020-14584P3HIGHCVSS 8.2v12.2.1.3.0v12.2.1.4.02020-07-15
CVE-2020-14584 [HIGH] CWE-79 CVE-2020-14584: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publishe Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interaction
nvd
CVE-2020-14585P3HIGHCVSS 8.2v11.1.1.9.0v12.2.1.3.0+1 more2020-07-15
CVE-2020-14585 [HIGH] CWE-79 CVE-2020-14585: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Mobile Serv Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Mobile Service). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human intera
nvd
CVE-2020-14571P3HIGHCVSS 7.2v11.1.1.9.0v12.2.1.3.0+1 more2020-07-15
CVE-2020-14571 [HIGH] CVE-2020-14571: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Mobile Serv Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Mobile Service). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publis
nvd
CVE-2025-61754P3MEDIUMCVSS 6.5v7.6.0.0.0v8.2.0.0.02025-10-21
CVE-2025-61754 [MEDIUM] CWE-267 CVE-2025-61754: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 7.6.0.0.0 and 8.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2019-2771P3HIGHCVSS 8.2v11.1.1.9.02019-07-23
CVE-2019-2771 [HIGH] CVE-2019-2771: Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (su Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Successful at
nvd
CVE-2020-14570P3HIGHCVSS 7.1v11.1.1.9.0v12.2.1.3.0+1 more2020-07-15
CVE-2020-14570 [HIGH] CVE-2020-14570: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Mobile Serv Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Mobile Service). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interaction f
nvd
CVE-2024-21084P4MEDIUMCVSS 5.8v7.0.0.0.0v12.2.1.4.02024-04-16
CVE-2024-21084 [MEDIUM] CWE-284 CVE-2024-21084: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Service Gateway). Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Service Gateway). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks
nvd
CVE-2023-21970P4MEDIUMCVSS 5.7v6.4.0.0.02023-04-18
CVE-2023-21970 [MEDIUM] CVE-2023-21970: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Security). The su Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Security). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interaction from a person other than the attacker. Succ
nvd
CVE-2025-30723P4MEDIUMCVSS 5.4v7.6.0.0.0v12.2.1.4.02025-04-15
CVE-2025-30723 [MEDIUM] CVE-2025-30723: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Sup Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized u
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1v5.5.0.0.0v11.1.1.9.0+2 more2019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2024-20987P4MEDIUMCVSS 5.4v12.2.1.4.02024-01-16
CVE-2024-20987 [MEDIUM] CVE-2024-20987: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). The Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interaction from a person other than the attacker and
nvd
CVE-2024-20979P4MEDIUMCVSS 5.4v6.4.0.0.0v7.0.0.0.0+1 more2024-01-16
CVE-2024-20979 [MEDIUM] CWE-285 CVE-2024-20979: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Suppo Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 6.4.0.0.0, 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interaction from a
nvd
CVE-2023-22105P4MEDIUMCVSS 5.4v6.4.0.0.0v7.0.0.0.02023-10-17
CVE-2023-22105 [MEDIUM] CVE-2023-22105: Vulnerability in the BI Publisher product of Oracle Analytics (component: Web Server). Supported ve Vulnerability in the BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 6.4.0.0.0 and 7.0.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human interaction from a person other than the attacker and
nvd
CVE-2019-2898P4MEDIUMCVSS 4.3v11.1.1.9.0v12.2.1.3.0+1 more2019-10-16
CVE-2019-2898 [MEDIUM] CVE-2019-2898: Vulnerability in the BI Publisher (formerly XML Publisher) product of Oracle Fusion Middleware (comp Vulnerability in the BI Publisher (formerly XML Publisher) product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Succ
nvd
CVE-2022-21523P4MEDIUMCVSS 4.3v12.2.1.3.0v12.2.1.4.02022-07-19
CVE-2022-21523 [MEDIUM] CVE-2022-21523: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publishe Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can resul
nvd
CVE-2023-21941P4MEDIUMCVSS 4.3v6.4.0.0.0v12.2.1.4.02023-04-18
CVE-2023-21941 [MEDIUM] CVE-2023-21941: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Suppo Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized rea
nvd