cbcvebase.

Oracle Business Intelligence vulnerabilities

85 known vulnerabilities affecting oracle/business_intelligence.

Total CVEs
85
CISA KEV
3
actively exploited
Public exploits
6
Exploited in wild
6
Severity breakdown
CRITICAL6HIGH27MEDIUM48LOW4

Vulnerabilities

Page 3 of 5
CVE-2017-10163P3MEDIUMCVSS 6.3v11.1.1.7.0v11.1.1.9.0+2 more2017-10-19
CVE-2017-10163 [MEDIUM] CVE-2017-10163: Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Midd Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Web General). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Busines
nvd
CVE-2019-2897P3MEDIUMCVSS 6.4v12.2.1.3.0v12.2.1.4.02019-10-16
CVE-2019-2897 [MEDIUM] CVE-2019-2897: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.
nvd
CVE-2020-14843P4HIGHCVSS 7.1v5.5.0.0.0v12.2.1.3.0+1 more2020-10-21
CVE-2020-14843 [HIGH] CVE-2020-14843: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterpri
nvd
CVE-2020-2537P4HIGHCVSS 7.1v12.2.1.3.0v12.2.1.4.02020-01-15
CVE-2020-2537 [HIGH] CVE-2020-2537: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. S
nvd
CVE-2019-3012P4MEDIUMCVSS 5.3v11.1.1.9.0v12.2.1.3.0+1 more2019-10-16
CVE-2019-3012 [MEDIUM] CVE-2019-3012: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: BI Platform Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Ente
nvd
CVE-2017-10058P4MEDIUMCVSS 6.9v11.1.1.9.0v12.2.1.1.0+1 more2017-08-08
CVE-2017-10058 [MEDIUM] CVE-2017-10058: Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Midd Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Web Administration). Supported versions that are affected are 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business In
nvd
CVE-2025-30759P4MEDIUMCVSS 6.1v7.6.0.0.0v8.2.0.0.0+1 more2025-07-15
CVE-2025-30759 [MEDIUM] CWE-284 CVE-2025-30759: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 7.6.0.0.0, 8.2.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterpr
nvd
CVE-2022-21492P4MEDIUMCVSS 6.1v5.9.0.0.02022-04-19
CVE-2022-21492 [MEDIUM] CVE-2022-21492: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Server). The supported version that is affected is 5.9.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful at
nvd
CVE-2022-21448P4MEDIUMCVSS 6.1v5.9.0.0.02022-04-19
CVE-2022-21448 [MEDIUM] CVE-2022-21448: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Visual Analyzer). The supported version that is affected is 5.9.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful att
nvd
CVE-2022-21419P4MEDIUMCVSS 6.1v5.5.0.0.0v5.9.0.0.02022-04-19
CVE-2022-21419 [MEDIUM] CVE-2022-21419: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Visual Analyzer). Supported versions that are affected are 5.5.0.0.0 and 5.9.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. S
nvd
CVE-2022-21609P4MEDIUMCVSS 5.7v5.9.0.0.02022-10-18
CVE-2022-21609 [MEDIUM] CVE-2022-21609: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Server). The supported version that is affected is 5.9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attac
nvd
CVE-2023-21965P4MEDIUMCVSS 5.7v6.4.0.0.02023-04-18
CVE-2023-21965 [MEDIUM] CVE-2023-21965: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks req
nvd
CVE-2023-21952P4MEDIUMCVSS 5.7v6.4.0.0.02023-04-18
CVE-2023-21952 [MEDIUM] CVE-2023-21952: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks req
nvd
CVE-2023-22020P4MEDIUMCVSS 5.4v6.4.0.0.0v7.0.0.0.02023-07-18
CVE-2023-22020 [MEDIUM] CVE-2023-22020: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 6.4.0.0.0 and 7.0.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successfu
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1v5.5.0.0.0v5.9.0.0.0+2 more2019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2016-0479P4MEDIUMCVSS 6.1v11.1.1.7.0v11.1.1.9.0+1 more2016-04-21
CVE-2016-0479 [MEDIUM] CVE-2016-0479: Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote attackers to affect confidentiality and integrity via vectors related to Analytics Scorecard.
nvd
CVE-2021-2003P4MEDIUMCVSS 5.4v5.5.0.0.0v11.1.1.9.0+2 more2021-01-20
CVE-2021-2003 [MEDIUM] CVE-2021-2003: Vulnerability in the Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (c Vulnerability in the Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web Dashboards). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Business Intelligence Ente
nvd
CVE-2021-2191P4MEDIUMCVSS 5.4v5.5.0.0.0v12.2.1.3.0+1 more2021-04-22
CVE-2021-2191 [MEDIUM] CVE-2021-2191: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterpris
nvd
CVE-2023-22011P4MEDIUMCVSS 5.4v6.4.0.0.0v7.0.0.0.02023-07-18
CVE-2023-22011 [MEDIUM] CVE-2023-22011: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 6.4.0.0.0 and 7.0.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successfu
nvd
CVE-2024-21001P4MEDIUMCVSS 5.4v7.0.0.0.02024-04-16
CVE-2024-21001 [MEDIUM] CVE-2024-21001: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks
nvd
Oracle Business Intelligence vulnerabilities | cvebase