Oracle Business Intelligence vulnerabilities
85 known vulnerabilities affecting oracle/business_intelligence.
Total CVEs
85
CISA KEV
3
actively exploited
Public exploits
4
Exploited in wild
4
Severity breakdown
CRITICAL6HIGH27MEDIUM48LOW4
Vulnerabilities
Page 2 of 5
CVE-2023-21952MEDIUMCVSS 5.7v6.4.0.0.02023-04-18
CVE-2023-21952 [MEDIUM] CVE-2023-21952: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks req
nvd
CVE-2023-21892MEDIUMCVSS 5.4v5.9.0.0.0v6.4.0.0.02023-01-18
CVE-2023-21892 [MEDIUM] CVE-2023-21892: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Visual Analyzer). Supported versions that are affected are 5.9.0.0.0 and 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Su
nvd
CVE-2023-21891MEDIUMCVSS 5.4v5.9.0.0.0v6.4.0.0.02023-01-18
CVE-2023-21891 [MEDIUM] CVE-2023-21891: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Visual Analyzer). Supported versions that are affected are 5.9.0.0.0 and 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Su
nvd
CVE-2023-21861MEDIUMCVSS 5.4v5.9.0.0.0v6.4.0.0.02023-01-18
CVE-2023-21861 [MEDIUM] CVE-2023-21861: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Visual Analyzer). Supported versions that are affected are 5.9.0.0.0 and 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Su
nvd
CVE-2022-21609MEDIUMCVSS 5.7v5.9.0.0.02022-10-18
CVE-2022-21609 [MEDIUM] CVE-2022-21609: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Server). The supported version that is affected is 5.9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attac
nvd
CVE-2022-21421HIGHCVSS 7.5v5.5.0.0.0v5.9.0.0.0+2 more2022-04-19
CVE-2022-21421 [HIGH] CVE-2022-21421: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 5.9.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intell
nvd
CVE-2022-21448MEDIUMCVSS 6.1v5.9.0.0.02022-04-19
CVE-2022-21448 [MEDIUM] CVE-2022-21448: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Visual Analyzer). The supported version that is affected is 5.9.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful att
nvd
CVE-2022-21419MEDIUMCVSS 6.1v5.5.0.0.0v5.9.0.0.02022-04-19
CVE-2022-21419 [MEDIUM] CVE-2022-21419: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Visual Analyzer). Supported versions that are affected are 5.5.0.0.0 and 5.9.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. S
nvd
CVE-2022-21492MEDIUMCVSS 6.1v5.9.0.0.02022-04-19
CVE-2022-21492 [MEDIUM] CVE-2022-21492: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Server). The supported version that is affected is 5.9.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful at
nvd
CVE-2022-23305CRITICALCVSS 9.8v5.9.0.0.0v12.2.1.3.0+1 more2022-01-18
CVE-2022-23305 [CRITICAL] CWE-89 CVE-2022-23305: By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter whe
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that ar
nvd
CVE-2022-23302HIGHCVSS 8.8v5.9.0.0.0v12.2.1.3.0+1 more2022-01-18
CVE-2022-23302 [HIGH] CVE-2022-23302: JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the att
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in r
nvd
CVE-2022-23307HIGHCVSS 8.8v5.9.0.0.0v12.2.1.3.0+1 more2022-01-18
CVE-2022-23307 [HIGH] CVE-2022-23307: CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chain
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
nvd
CVE-2021-45105MEDIUMCVSS 5.9v5.5.0.0.02021-12-18
CVE-2021-45105 [MEDIUM] CWE-20 CVE-2021-45105: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from u
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
nvd
CVE-2021-4104HIGHCVSS 7.5v5.9.0.0.0v12.2.1.3.0+1 more2021-12-14
CVE-2021-4104 [HIGH] CWE-502 CVE-2021-4104: JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has wr
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228.
nvd
CVE-2021-2456CRITICALCVSS 9.8v12.2.1.4.02021-07-21
CVE-2021-2456 [CRITICAL] CVE-2021-2456: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Success
nvd
CVE-2021-30468HIGHCVSS 7.5v5.5.0.0.0v5.9.0.0.0+2 more2021-06-16
CVE-2021-30468 [HIGH] CWE-400 CVE-2021-30468: A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malforme
A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF versions prior to 3.4.4; Apache CXF versions prior to 3.3.11.
nvd
CVE-2021-2152MEDIUMCVSS 4.0v5.5.0.0.0v11.1.1.9.0+2 more2021-04-22
CVE-2021-2152 [MEDIUM] CVE-2021-2152: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Int
nvd
CVE-2021-2191MEDIUMCVSS 5.4v5.5.0.0.0v12.2.1.3.0+1 more2021-04-22
CVE-2021-2191 [MEDIUM] CVE-2021-2191: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterpris
nvd
CVE-2021-22696HIGHCVSS 7.5v5.5.0.0.0v5.9.0.0.0+2 more2021-04-02
CVE-2021-22696 [HIGH] CWE-400 CVE-2021-22696: CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to que
CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)). Instead of sending a JWT token as a "request" parameter, the spec also supports specifying a URI from which to retrieve a JWT token from via the "reques
nvd
CVE-2021-23840HIGHCVSS 7.5v5.5.0.0.0v5.9.0.0.0+2 more2021-02-16
CVE-2021-23840 [HIGH] CWE-190 CVE-2021-23840: Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length ar
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. Th
nvd