Oracle Business Intelligence vulnerabilities
85 known vulnerabilities affecting oracle/business_intelligence.
Total CVEs
85
CISA KEV
3
actively exploited
Public exploits
6
Exploited in wild
6
Severity breakdown
CRITICAL6HIGH27MEDIUM48LOW4
Vulnerabilities
Page 2 of 5
CVE-2019-2900P3HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02019-10-16
CVE-2019-2900 [HIGH] CVE-2019-2900: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. S
nvd
CVE-2022-21421P3HIGHCVSS 7.5v5.5.0.0.0v5.9.0.0.0+2 more2022-04-19
CVE-2022-21421 [HIGH] CVE-2022-21421: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 5.9.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intell
nvd
CVE-2021-22696P3HIGHCVSS 7.5v5.5.0.0.0v5.9.0.0.0+2 more2021-04-02
CVE-2021-22696 [HIGH] CWE-400 CVE-2021-22696: CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to que
CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)). Instead of sending a JWT token as a "request" parameter, the spec also supports specifying a URI from which to retrieve a JWT token from via the "reques
nvd
CVE-2016-3446P3HIGHCVSS 8.3v11.1.1.7.0v11.1.1.9.02016-07-21
CVE-2016-3446 [HIGH] CVE-2016-3446: Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle
Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 11.1.1.7.0 and 11.1.1.9.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Analytics Web Administration.
nvd
CVE-2020-13954P3MEDIUMCVSS 6.1v5.5.0.0.0v5.9.0.0.0+2 more2020-11-12
CVE-2020-13954 [MEDIUM] CVE-2020-13954: By default, Apache CXF creates a /services page containing a listing of the available endpoint names
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and
nvd
CVE-2021-2025P3HIGHCVSS 8.2v5.5.0.0.0v11.1.1.9.0+2 more2021-01-20
CVE-2021-2025 [HIGH] CVE-2021-2025: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelli
nvd
CVE-2017-10060P3HIGHCVSS 8.2v11.1.1.7.0v11.1.1.9.0+2 more2017-10-19
CVE-2017-10060 [HIGH] CVE-2017-10060: Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Midd
Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Web General). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business
nvd
CVE-2025-53049P3HIGHCVSS 8.4v7.6.0.0.0v8.2.0.0.02025-10-21
CVE-2025-53049 [HIGH] CWE-284 CVE-2025-53049: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Administration). Supported versions that are affected are 7.6.0.0.0 and 8.2.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise
nvd
CVE-2019-1559P3MEDIUMCVSS 5.9v11.1.1.9.0v12.2.1.3.0+1 more2019-02-27
CVE-2019-1559 [MEDIUM] CWE-203 CVE-2019-1559: If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to sen
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behave
nvd
CVE-2017-10068P3HIGHCVSS 8.2v12.2.1.3.02018-01-18
CVE-2017-10068 [HIGH] CVE-2017-10068: Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Midd
Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Web Dashboards). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. S
nvd
CVE-2018-3204P3HIGHCVSS 8.2v12.2.1.3.02018-10-17
CVE-2018-3204 [HIGH] CVE-2018-3204: Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Midd
Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Server). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful
nvd
CVE-2020-14690P3HIGHCVSS 8.2v5.5.0.0.0v11.1.1.9.0+2 more2020-07-15
CVE-2020-14690 [HIGH] CVE-2020-14690: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intellige
nvd
CVE-2016-7103P3MEDIUMCVSS 6.1v12.2.1.3.0v12.2.1.4.02017-03-15
CVE-2016-7103 [MEDIUM] CWE-79 CVE-2016-7103: Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
nvd
CVE-2016-3544P3HIGHCVSS 7.6v11.1.1.7.0v11.1.1.9.0+1 more2016-07-21
CVE-2016-3544 [HIGH] CVE-2016-3544: Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle
Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 11.2.1.0.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to Analytics Web General.
nvd
CVE-2020-14766P3HIGHCVSS 7.1v5.5.0.0.0v11.1.1.9.0+2 more2020-10-21
CVE-2020-14766 [HIGH] CVE-2020-14766: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web Administration). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business
nvd
CVE-2021-23841P3MEDIUMCVSS 5.9v5.5.0.0.0v5.9.0.0.0+2 more2021-02-16
CVE-2021-23841 [MEDIUM] CWE-476 CVE-2021-23841: The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This ma
nvd
CVE-2018-2715P3MEDIUMCVSS 6.5v12.2.1.2.0v12.2.1.3.02018-01-18
CVE-2018-2715 [MEDIUM] CVE-2018-2715: Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Midd
Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: BI Platform Security). Supported versions that are affected are 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise E
nvd
CVE-2023-21910P3MEDIUMCVSS 6.5v6.4.0.0.0v12.2.1.4.02023-04-18
CVE-2023-21910 [MEDIUM] CVE-2023-21910: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General). Supported versions that are affected are 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Suc
nvd
CVE-2026-21976P3HIGHCVSS 7.1v7.6.0.0.0v8.2.0.0.02026-01-20
CVE-2026-21976 [HIGH] CVE-2026-21976: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Oracle Analytics Cloud). Supported versions that are affected are 7.6.0.0.0 and 8.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes t
nvd
CVE-2020-1971P3MEDIUMCVSS 5.9v5.5.0.0.0v5.9.0.0.0+2 more2020-12-08
CVE-2020-1971 [MEDIUM] CWE-476 CVE-2020-1971: The X.509 GeneralName type is a generic type for representing different types of names. One of those
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A
nvd