Oracle Business Intelligence vulnerabilities

85 known vulnerabilities affecting oracle/business_intelligence.

Total CVEs
85
CISA KEV
3
actively exploited
Public exploits
4
Exploited in wild
4
Severity breakdown
CRITICAL6HIGH27MEDIUM48LOW4

Vulnerabilities

Page 3 of 5
CVE-2021-23841MEDIUMCVSS 5.9v5.5.0.0.0v5.9.0.0.0+2 more2021-02-16
CVE-2021-23841 [MEDIUM] CWE-476 CVE-2021-23841: The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This ma
nvd
CVE-2021-23839LOWCVSS 3.7v5.5.0.0.0v5.9.0.0.0+2 more2021-02-16
CVE-2021-23839 [LOW] CWE-327 CVE-2021-23839: OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configur OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configured to support both SSLv2 and more recent SSL and TLS versions then a check is made for a version rollback attack when unpadding an RSA signature. Clients that support SSL or TLS versions greater than SSLv2 are supposed to use a special form of padding. A
nvd
CVE-2021-2025HIGHCVSS 8.2v5.5.0.0.0v11.1.1.9.0+2 more2021-01-20
CVE-2021-2025 [HIGH] CVE-2021-2025: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelli
nvd
CVE-2021-2041HIGHCVSS 8.1v12.2.1.3.0v12.2.1.4.02021-01-20
CVE-2021-2041 [HIGH] CVE-2021-2041: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Succ
nvd
CVE-2021-2003MEDIUMCVSS 5.4v5.5.0.0.0v11.1.1.9.0+2 more2021-01-20
CVE-2021-2003 [MEDIUM] CVE-2021-2003: Vulnerability in the Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (c Vulnerability in the Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web Dashboards). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Business Intelligence Ente
nvd
CVE-2021-2005MEDIUMCVSS 4.7v12.2.1.3.0v12.2.1.4.02021-01-20
CVE-2021-2005 [MEDIUM] CVE-2021-2005: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: BI Platform Security). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Editi
nvd
CVE-2020-17530CRITICALCVSS 9.8KEVPoCv12.2.1.3.0v12.2.1.4.02020-12-11
CVE-2020-17530 [CRITICAL] CWE-917 CVE-2020-17530: Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
nvd
CVE-2020-1971MEDIUMCVSS 5.9v5.5.0.0.0v5.9.0.0.0+2 more2020-12-08
CVE-2020-1971 [MEDIUM] CWE-476 CVE-2020-1971: The X.509 GeneralName type is a generic type for representing different types of names. One of those The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A
nvd
CVE-2019-17566HIGHCVSS 7.5v5.5.0.0.0v5.9.0.0.0+2 more2020-11-12
CVE-2019-17566 [HIGH] CWE-918 CVE-2019-17566: Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by th Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
nvd
CVE-2020-13954MEDIUMCVSS 6.1v5.5.0.0.0v5.9.0.0.0+2 more2020-11-12
CVE-2020-13954 [MEDIUM] CVE-2020-13954: By default, Apache CXF creates a /services page containing a listing of the available endpoint names By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and
nvd
CVE-2020-14766HIGHCVSS 7.1v5.5.0.0.0v11.1.1.9.0+2 more2020-10-21
CVE-2020-14766 [HIGH] CVE-2020-14766: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web Administration). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business
nvd
CVE-2020-14864HIGHCVSS 7.5KEVPoCv5.5.0.0.0v12.2.1.3.0+1 more2020-10-21
CVE-2020-14864 [HIGH] CWE-22 CVE-2020-14864: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterp
nvd
CVE-2020-14843HIGHCVSS 7.1v5.5.0.0.0v12.2.1.3.0+1 more2020-10-21
CVE-2020-14843 [HIGH] CVE-2020-14843: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterpri
nvd
CVE-2020-14815HIGHCVSS 8.2v5.5.0.0.0v12.2.1.3.0+1 more2020-10-21
CVE-2020-14815 [HIGH] CVE-2020-14815: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterpri
nvd
CVE-2020-14690HIGHCVSS 8.2v5.5.0.0.0v11.1.1.9.0+2 more2020-07-15
CVE-2020-14690 [HIGH] CVE-2020-14690: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intellige
nvd
CVE-2020-14609HIGHCVSS 8.6v5.5.0.0.0v11.1.1.9.0+2 more2020-07-15
CVE-2020-14609 [HIGH] CVE-2020-14609: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web Answers). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intel
nvd
CVE-2020-14626HIGHCVSS 8.1v5.5.0.0.0v11.1.1.9.0+2 more2020-07-15
CVE-2020-14626 [HIGH] CVE-2020-14626: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Int
nvd
CVE-2020-14548LOWCVSS 3.4v12.2.1.3.0v12.2.1.4.02020-07-15
CVE-2020-14548 [LOW] CVE-2020-14548: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edi
nvd
CVE-2020-9480CRITICALCVSS 9.8ExploitedPoCv5.5.0.0.02020-06-23
CVE-2020-9480 [CRITICAL] CWE-306 CVE-2020-9480: In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to requi In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to exe
nvd
CVE-2020-11023MEDIUMCVSS 6.1KEVPoCv5.9.0.0.02020-04-29
CVE-2020-11023 [MEDIUM] CWE-79 CVE-2020-11023: In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
nvd