Oracle Bi Publisher vulnerabilities

36 known vulnerabilities affecting oracle/bi_publisher.

Total CVEs
36
CISA KEV
0
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH20MEDIUM13

Vulnerabilities

Page 2 of 2
CVE-2021-2400HIGHCVSS 7.5v5.5.0.0.0v11.1.1.9.0+2 more2021-07-21
CVE-2021-2400 [HIGH] CVE-2021-2400: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vul
nvd
CVE-2021-2391HIGHCVSS 8.8v5.5.0.0.0v11.1.1.9.0+2 more2021-07-21
CVE-2021-2391 [HIGH] CVE-2021-2391: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Scheduler). Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Scheduler). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability ca
nvd
CVE-2021-2396HIGHCVSS 8.8v5.5.0.0.0v11.1.1.9.0+2 more2021-07-21
CVE-2021-2396 [HIGH] CVE-2021-2396: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vuln
nvd
CVE-2021-2401MEDIUMCVSS 5.3v5.5.0.0.0v11.1.1.9.0+2 more2021-07-21
CVE-2021-2401 [MEDIUM] CWE-611 CVE-2021-2401: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks o
nvd
CVE-2021-21346CRITICALCVSS 9.8v5.5.0.0.0v12.2.1.3.0+1 more2021-03-23
CVE-2021-21346 [MEDIUM] CWE-434 CVE-2021-21346: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4. XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security fram
nvd
CVE-2020-14571HIGHCVSS 7.2v11.1.1.9.0v12.2.1.3.0+1 more2020-07-15
CVE-2020-14571 [HIGH] CVE-2020-14571: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Mobile Serv Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Mobile Service). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publis
nvd
CVE-2020-14584HIGHCVSS 8.2v12.2.1.3.0v12.2.1.4.02020-07-15
CVE-2020-14584 [HIGH] CWE-79 CVE-2020-14584: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publishe Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interaction
nvd
CVE-2020-14570HIGHCVSS 7.1v11.1.1.9.0v12.2.1.3.0+1 more2020-07-15
CVE-2020-14570 [HIGH] CVE-2020-14570: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Mobile Serv Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Mobile Service). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interaction f
nvd
CVE-2020-14585HIGHCVSS 8.2v11.1.1.9.0v12.2.1.3.0+1 more2020-07-15
CVE-2020-14585 [HIGH] CWE-79 CVE-2020-14585: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Mobile Serv Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Mobile Service). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human intera
nvd
CVE-2019-10219MEDIUMCVSS 6.1v5.5.0.0.0v11.1.1.9.0+2 more2019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2019-2898MEDIUMCVSS 4.3v11.1.1.9.0v12.2.1.3.0+1 more2019-10-16
CVE-2019-2898 [MEDIUM] CVE-2019-2898: Vulnerability in the BI Publisher (formerly XML Publisher) product of Oracle Fusion Middleware (comp Vulnerability in the BI Publisher (formerly XML Publisher) product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Succ
nvd
CVE-2019-2771HIGHCVSS 8.2v11.1.1.9.02019-07-23
CVE-2019-2771 [HIGH] CVE-2019-2771: Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (su Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Successful at
nvd
CVE-2019-2768HIGHCVSS 7.5v11.1.1.9.02019-07-23
CVE-2019-2768 [HIGH] CVE-2019-2768: Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (su Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The supported version that is affected is 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Successful attacks of this
nvd
CVE-2019-2767HIGHCVSS 7.2ExploitedPoCv11.1.1.9.02019-07-23
CVE-2019-2767 [HIGH] CVE-2019-2767: Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (su Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The supported version that is affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher)
nvd
CVE-2019-11358MEDIUMCVSS 6.1ExploitedPoCv5.5.0.0.0v12.2.1.3.0+1 more2019-04-20
CVE-2019-11358 [MEDIUM] CWE-1321 CVE-2019-11358: jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(t jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
nvd
CVE-2017-5645CRITICALCVSS 9.8PoCv11.1.1.7.0v11.1.1.9.0+2 more2017-04-17
CVE-2017-5645 [CRITICAL] CWE-502 CVE-2017-5645: In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive s In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
nvd