Oracle Business Intelligence vulnerabilities
99 known vulnerabilities affecting oracle/business_intelligence.
Total CVEs
99
CISA KEV
3
actively exploited
Public exploits
6
Exploited in wild
6
Severity breakdown
CRITICAL6HIGH41MEDIUM48LOW4
Vulnerabilities
Page 2 of 5
CVE-2020-14609P3HIGHCVSS 8.6v5.5.0.0.0v11.1.1.9.0+2 more2020-07-15
CVE-2020-14609 [HIGH] CVE-2020-14609: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web Answers). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intel
nvd
CVE-2026-61302P3HIGHCVSS 8.2v8.2.0.0.0v26.01.0.0.02026-08-18
CVE-2026-61302 [HIGH] CWE-284 CVE-2026-61302: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Pod Admin). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Success
nvd
CVE-2026-71096P3HIGHCVSS 8.2v8.2.0.0.0v12.2.1.4.0+1 more2026-08-18
CVE-2026-71096 [HIGH] CWE-284 CVE-2026-71096: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Ent
nvd
CVE-2021-2041P3HIGHCVSS 8.1v12.2.1.3.0v12.2.1.4.02021-01-20
CVE-2021-2041 [HIGH] CVE-2021-2041: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Succ
nvd
CVE-2026-71107P3HIGHCVSS 7.5v8.2.0.0.0v26.01.0.0.02026-08-18
CVE-2026-71107 [HIGH] CWE-284 CVE-2026-71107: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.
nvd
CVE-2026-71061P3HIGHCVSS 7.5v8.2.0.0.0v26.01.0.0.02026-08-18
CVE-2026-71061 [HIGH] CWE-284 CVE-2026-71061: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Editi
nvd
CVE-2020-14626P3HIGHCVSS 8.1v5.5.0.0.0v11.1.1.9.0+2 more2020-07-15
CVE-2020-14626 [HIGH] CVE-2020-14626: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Int
nvd
CVE-2021-30468P3HIGHCVSS 7.5v5.5.0.0.0v5.9.0.0.0+2 more2021-06-16
CVE-2021-30468 [HIGH] CWE-400 CVE-2021-30468: A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malforme
A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF versions prior to 3.4.4; Apache CXF versions prior to 3.3.11.
nvd
CVE-2026-71056P3HIGHCVSS 7.7v8.2.0.0.0v12.2.1.4.0+1 more2026-08-18
CVE-2026-71056 [HIGH] CWE-284 CVE-2026-71056: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Editi
nvd
CVE-2019-2900P3HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02019-10-16
CVE-2019-2900 [HIGH] CVE-2019-2900: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. S
nvd
CVE-2022-21421P3HIGHCVSS 7.5v5.5.0.0.0v5.9.0.0.0+2 more2022-04-19
CVE-2022-21421 [HIGH] CVE-2022-21421: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 5.9.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intell
nvd
CVE-2021-22696P3HIGHCVSS 7.5v5.5.0.0.0v5.9.0.0.0+2 more2021-04-02
CVE-2021-22696 [HIGH] CWE-400 CVE-2021-22696: CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to que
CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)). Instead of sending a JWT token as a "request" parameter, the spec also supports specifying a URI from which to retrieve a JWT token from via the "reques
nvd
CVE-2016-3446P3HIGHCVSS 8.3v11.1.1.7.0v11.1.1.9.02016-07-21
CVE-2016-3446 [HIGH] CVE-2016-3446: Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle
Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 11.1.1.7.0 and 11.1.1.9.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Analytics Web Administration.
nvd
CVE-2026-71099P3HIGHCVSS 7.2v26.01.0.0.02026-08-18
CVE-2026-71099 [HIGH] CWE-284 CVE-2026-71099: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Answers). The supported version that is affected is 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successf
nvd
CVE-2021-2025P3HIGHCVSS 8.2v5.5.0.0.0v11.1.1.9.0+2 more2021-01-20
CVE-2021-2025 [HIGH] CVE-2021-2025: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelli
nvd
CVE-2026-71122P3HIGHCVSS 8.0v26.01.0.0.02026-08-18
CVE-2026-71122 [HIGH] CWE-284 CVE-2026-71122: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the
nvd
CVE-2020-13954P3MEDIUMCVSS 6.1v5.5.0.0.0v5.9.0.0.0+2 more2020-11-12
CVE-2020-13954 [MEDIUM] CVE-2020-13954: By default, Apache CXF creates a /services page containing a listing of the available endpoint names
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and
nvd
CVE-2017-10060P3HIGHCVSS 8.2v11.1.1.7.0v11.1.1.9.0+2 more2017-10-19
CVE-2017-10060 [HIGH] CVE-2017-10060: Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Midd
Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Web General). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business
nvd
CVE-2019-1559P3MEDIUMCVSS 5.9v11.1.1.9.0v12.2.1.3.0+1 more2019-02-27
CVE-2019-1559 [MEDIUM] CWE-203 CVE-2019-1559: If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to sen
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behave
nvd
CVE-2026-71097P3HIGHCVSS 7.8v26.01.0.0.02026-08-18
CVE-2026-71097 [HIGH] CWE-284 CVE-2026-71097: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compro
nvd