Oracle Business Intelligence vulnerabilities
85 known vulnerabilities affecting oracle/business_intelligence.
Total CVEs
85
CISA KEV
3
actively exploited
Public exploits
6
Exploited in wild
6
Severity breakdown
CRITICAL6HIGH27MEDIUM48LOW4
Vulnerabilities
Page 4 of 5
CVE-2023-21892P4MEDIUMCVSS 5.4v5.9.0.0.0v6.4.0.0.02023-01-18
CVE-2023-21892 [MEDIUM] CVE-2023-21892: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Visual Analyzer). Supported versions that are affected are 5.9.0.0.0 and 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Su
nvd
CVE-2023-21891P4MEDIUMCVSS 5.4v5.9.0.0.0v6.4.0.0.02023-01-18
CVE-2023-21891 [MEDIUM] CVE-2023-21891: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Visual Analyzer). Supported versions that are affected are 5.9.0.0.0 and 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Su
nvd
CVE-2023-21861P4MEDIUMCVSS 5.4v5.9.0.0.0v6.4.0.0.02023-01-18
CVE-2023-21861 [MEDIUM] CVE-2023-21861: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Visual Analyzer). Supported versions that are affected are 5.9.0.0.0 and 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Su
nvd
CVE-2023-22061P4MEDIUMCVSS 5.4v6.4.0.0.02023-07-18
CVE-2023-22061 [MEDIUM] CVE-2023-22061: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Visual Analyzer). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks requ
nvd
CVE-2023-22082P4MEDIUMCVSS 5.4v6.4.0.0.0v7.0.0.0.02023-10-17
CVE-2023-22082 [MEDIUM] CVE-2023-22082: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Pod Admin). Supported versions that are affected are 6.4.0.0.0 and 7.0.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attac
nvd
CVE-2024-21139P4MEDIUMCVSS 5.4v7.0.0.0.0v7.6.0.0.0+1 more2024-07-16
CVE-2024-21139 [MEDIUM] CVE-2024-21139: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Answers). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise E
nvd
CVE-2024-20913P4MEDIUMCVSS 5.4v12.2.1.4.02024-02-17
CVE-2024-20913 [MEDIUM] CVE-2024-20913: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attack
nvd
CVE-2024-21064P4MEDIUMCVSS 5.4v7.0.0.0.0v12.2.1.4.02024-04-16
CVE-2024-21064 [MEDIUM] CWE-200 CVE-2024-21064: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Answers). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edit
nvd
CVE-2019-14862P4MEDIUMCVSS 6.1v5.5.0.0.0v12.2.1.3.0+1 more2020-01-02
CVE-2019-14862 [MEDIUM] CWE-79 CVE-2019-14862: There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
nvd
CVE-2016-3433P4MEDIUMCVSS 5.4v11.1.1.7.0v11.1.1.9.02016-07-21
CVE-2016-3433 [MEDIUM] CVE-2016-3433: Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle
Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 11.1.1.7.0 and 11.1.1.9.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to Analytics Web Administration.
nvd
CVE-2024-20904P4MEDIUMCVSS 5.0v6.4.0.0.0v12.2.1.4.02024-01-16
CVE-2024-20904 [MEDIUM] CWE-200 CVE-2024-20904: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Pod Admin). Supported versions that are affected are 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While t
nvd
CVE-2016-0468P4MEDIUMCVSS 5.4v11.1.1.7.0v11.1.1.9.0+1 more2016-04-21
CVE-2016-0468 [MEDIUM] CVE-2016-0468: Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle
Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to Analytics Web General.
nvd
CVE-2021-2005P4MEDIUMCVSS 4.7v12.2.1.3.0v12.2.1.4.02021-01-20
CVE-2021-2005 [MEDIUM] CVE-2021-2005: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: BI Platform Security). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Editi
nvd
CVE-2020-2535P4MEDIUMCVSS 4.7v12.2.1.3.0v12.2.1.4.02020-01-15
CVE-2020-2535 [MEDIUM] CVE-2020-2535: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Server). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.
nvd
CVE-2023-22109P4MEDIUMCVSS 4.6v6.4.0.0.0v7.0.0.0.0+1 more2023-10-17
CVE-2023-22109 [MEDIUM] CVE-2023-22109: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Dashboards). Supported versions that are affected are 6.4.0.0.0, 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterpris
nvd
CVE-2023-22013P4MEDIUMCVSS 4.3v6.4.0.0.0v7.0.0.0.02023-07-18
CVE-2023-22013 [MEDIUM] CVE-2023-22013: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 6.4.0.0.0 and 7.0.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successfu
nvd
CVE-2023-22012P4MEDIUMCVSS 4.3v7.0.0.0.02023-07-18
CVE-2023-22012 [MEDIUM] CVE-2023-22012: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of
nvd
CVE-2024-21099P4MEDIUMCVSS 4.3v7.0.0.0.02024-04-16
CVE-2024-21099 [MEDIUM] CWE-125 CVE-2024-21099: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Data Visualization). The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful a
nvd
CVE-2021-23839P4LOWCVSS 3.7v5.5.0.0.0v5.9.0.0.0+2 more2021-02-16
CVE-2021-23839 [LOW] CWE-327 CVE-2021-23839: OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configur
OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configured to support both SSLv2 and more recent SSL and TLS versions then a check is made for a version rollback attack when unpadding an RSA signature. Clients that support SSL or TLS versions greater than SSLv2 are supposed to use a special form of padding. A
nvd
CVE-2023-22021P4MEDIUMCVSS 4.3v6.4.0.0.0v7.0.0.0.02023-07-18
CVE-2023-22021 [MEDIUM] CVE-2023-22021: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 6.4.0.0.0 and 7.0.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successfu
nvd