cbcvebase.

Oracle Business Intelligence vulnerabilities

85 known vulnerabilities affecting oracle/business_intelligence.

Total CVEs
85
CISA KEV
3
actively exploited
Public exploits
6
Exploited in wild
6
Severity breakdown
CRITICAL6HIGH27MEDIUM48LOW4

Vulnerabilities

Page 1 of 5
CVE-2020-17530P1CRITICALCVSS 9.8KEVPoCv12.2.1.3.0v12.2.1.4.02020-12-11
CVE-2020-17530 [CRITICAL] CWE-917 CVE-2020-17530: Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
nvd
CVE-2020-14864P1HIGHCVSS 7.5KEVPoCv5.5.0.0.0v12.2.1.3.0+1 more2020-10-21
CVE-2020-14864 [HIGH] CWE-22 CVE-2020-14864: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterp
nvd
CVE-2020-11023P1MEDIUMCVSS 6.1KEVPoCv5.9.0.0.02020-04-29
CVE-2020-11023 [MEDIUM] CWE-79 CVE-2020-11023: In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
nvd
CVE-2021-45105P1MEDIUMCVSS 5.9ExploitedPoCRansomwarev5.5.0.0.02021-12-18
CVE-2021-45105 [MEDIUM] CWE-20 CVE-2021-45105: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from u Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
nvd
CVE-2021-4104P1HIGHCVSS 7.5ExploitedPoCv5.9.0.0.0v12.2.1.3.0+1 more2021-12-14
CVE-2021-4104 [HIGH] CWE-502 CVE-2021-4104: JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has wr JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228.
nvd
CVE-2020-9480P1CRITICALCVSS 9.8ExploitedPoCv5.5.0.0.02020-06-23
CVE-2020-9480 [CRITICAL] CWE-306 CVE-2020-9480: In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to requi In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to exe
nvd
CVE-2021-2456P2CRITICALCVSS 9.8v12.2.1.4.02021-07-21
CVE-2021-2456 [CRITICAL] CVE-2021-2456: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Success
nvd
CVE-2020-2950P2CRITICALCVSS 9.8v5.5.0.0.0v11.1.1.9.0+2 more2020-04-15
CVE-2020-2950 [CRITICAL] CVE-2020-2950: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Int
nvd
CVE-2022-23305P2CRITICALCVSS 9.8v5.9.0.0.0v12.2.1.3.0+1 more2022-01-18
CVE-2022-23305 [CRITICAL] CWE-89 CVE-2022-23305: By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter whe By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that ar
nvd
CVE-2022-23302P2HIGHCVSS 8.8v5.9.0.0.0v12.2.1.3.0+1 more2022-01-18
CVE-2022-23302 [HIGH] CVE-2022-23302: JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the att JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in r
nvd
CVE-2022-23307P2HIGHCVSS 8.8v5.9.0.0.0v12.2.1.3.0+1 more2022-01-18
CVE-2022-23307 [HIGH] CVE-2022-23307: CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chain CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
nvd
CVE-2021-23840P3HIGHCVSS 7.5v5.5.0.0.0v5.9.0.0.0+2 more2021-02-16
CVE-2021-23840 [HIGH] CWE-190 CVE-2021-23840: Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length ar Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. Th
nvd
CVE-2018-8013P3CRITICALCVSS 9.8v11.1.1.7.0v11.1.1.9.0+2 more2018-05-24
CVE-2018-8013 [CRITICAL] CWE-502 CVE-2018-8013: In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
nvd
CVE-2019-17566P3HIGHCVSS 7.5v5.5.0.0.0v5.9.0.0.0+2 more2020-11-12
CVE-2019-17566 [HIGH] CWE-918 CVE-2019-17566: Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by th Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
nvd
CVE-2020-14815P3HIGHCVSS 8.2v5.5.0.0.0v12.2.1.3.0+1 more2020-10-21
CVE-2020-14815 [HIGH] CVE-2020-14815: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterpri
nvd
CVE-2019-2905P3HIGHCVSS 8.6v12.2.1.3.0v12.2.1.4.02019-10-16
CVE-2019-2905 [HIGH] CVE-2019-2905: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While
nvd
CVE-2020-14609P3HIGHCVSS 8.6v5.5.0.0.0v11.1.1.9.0+2 more2020-07-15
CVE-2020-14609 [HIGH] CVE-2020-14609: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web Answers). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intel
nvd
CVE-2021-2041P3HIGHCVSS 8.1v12.2.1.3.0v12.2.1.4.02021-01-20
CVE-2021-2041 [HIGH] CVE-2021-2041: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Succ
nvd
CVE-2020-14626P3HIGHCVSS 8.1v5.5.0.0.0v11.1.1.9.0+2 more2020-07-15
CVE-2020-14626 [HIGH] CVE-2020-14626: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Int
nvd
CVE-2021-30468P3HIGHCVSS 7.5v5.5.0.0.0v5.9.0.0.0+2 more2021-06-16
CVE-2021-30468 [HIGH] CWE-400 CVE-2021-30468: A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malforme A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF versions prior to 3.4.4; Apache CXF versions prior to 3.3.11.
nvd
Oracle Business Intelligence vulnerabilities | cvebase