Oracle Business Intelligence vulnerabilities

85 known vulnerabilities affecting oracle/business_intelligence.

Total CVEs
85
CISA KEV
3
actively exploited
Public exploits
4
Exploited in wild
4
Severity breakdown
CRITICAL6HIGH27MEDIUM48LOW4

Vulnerabilities

Page 4 of 5
CVE-2020-2950CRITICALCVSS 9.8v5.5.0.0.0v11.1.1.9.0+2 more2020-04-15
CVE-2020-2950 [CRITICAL] CVE-2020-2950: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Int
nvd
CVE-2020-2537HIGHCVSS 7.1v12.2.1.3.0v12.2.1.4.02020-01-15
CVE-2020-2537 [HIGH] CVE-2020-2537: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. S
nvd
CVE-2020-2535MEDIUMCVSS 4.7v12.2.1.3.0v12.2.1.4.02020-01-15
CVE-2020-2535 [MEDIUM] CVE-2020-2535: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Server). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.
nvd
CVE-2020-2531LOWCVSS 3.1v12.2.1.3.0v12.2.1.4.02020-01-15
CVE-2020-2531 [LOW] CVE-2020-2531: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: BI Platform Security). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Editio
nvd
CVE-2019-14862MEDIUMCVSS 6.1v5.5.0.0.0v12.2.1.3.0+1 more2020-01-02
CVE-2019-14862 [MEDIUM] CWE-79 CVE-2019-14862: There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
nvd
CVE-2019-10219MEDIUMCVSS 6.1v5.5.0.0.0v5.9.0.0.0+2 more2019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2019-2900HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02019-10-16
CVE-2019-2900 [HIGH] CVE-2019-2900: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. S
nvd
CVE-2019-2905HIGHCVSS 8.6v12.2.1.3.0v12.2.1.4.02019-10-16
CVE-2019-2905 [HIGH] CVE-2019-2905: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While
nvd
CVE-2019-3012MEDIUMCVSS 5.3v11.1.1.9.0v12.2.1.3.0+1 more2019-10-16
CVE-2019-3012 [MEDIUM] CVE-2019-3012: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: BI Platform Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Ente
nvd
CVE-2019-2897MEDIUMCVSS 6.4v12.2.1.3.0v12.2.1.4.02019-10-16
CVE-2019-2897 [MEDIUM] CVE-2019-2897: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.
nvd
CVE-2019-2605LOWCVSS 3.4v11.1.1.9.0v12.2.1.3.0+1 more2019-04-23
CVE-2019-2605 [LOW] CVE-2019-2605: Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Midd Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Web Catalog). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterpris
nvd
CVE-2019-1559MEDIUMCVSS 5.9v11.1.1.9.0v12.2.1.3.0+1 more2019-02-27
CVE-2019-1559 [MEDIUM] CWE-203 CVE-2019-1559: If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to sen If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behave
nvd
CVE-2018-3204HIGHCVSS 8.2v12.2.1.3.02018-10-17
CVE-2018-3204 [HIGH] CVE-2018-3204: Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Midd Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Server). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful
nvd
CVE-2018-8013CRITICALCVSS 9.8v11.1.1.7.0v11.1.1.9.0+2 more2018-05-24
CVE-2018-8013 [CRITICAL] CWE-502 CVE-2018-8013: In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
nvd
CVE-2017-10068HIGHCVSS 8.2v12.2.1.3.02018-01-18
CVE-2017-10068 [HIGH] CVE-2017-10068: Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Midd Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Web Dashboards). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. S
nvd
CVE-2018-2715MEDIUMCVSS 6.5v12.2.1.2.0v12.2.1.3.02018-01-18
CVE-2018-2715 [MEDIUM] CVE-2018-2715: Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Midd Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: BI Platform Security). Supported versions that are affected are 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise E
nvd
CVE-2017-10060HIGHCVSS 8.2v11.1.1.7.0v11.1.1.9.0+2 more2017-10-19
CVE-2017-10060 [HIGH] CVE-2017-10060: Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Midd Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Web General). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business
nvd
CVE-2017-10163MEDIUMCVSS 6.3v11.1.1.7.0v11.1.1.9.0+2 more2017-10-19
CVE-2017-10163 [MEDIUM] CVE-2017-10163: Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Midd Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Web General). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Busines
nvd
CVE-2017-10058MEDIUMCVSS 6.9v11.1.1.9.0v12.2.1.1.0+1 more2017-08-08
CVE-2017-10058 [MEDIUM] CVE-2017-10058: Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Midd Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Web Administration). Supported versions that are affected are 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business In
nvd
CVE-2016-7103MEDIUMCVSS 6.1v12.2.1.3.0v12.2.1.4.02017-03-15
CVE-2016-7103 [MEDIUM] CWE-79 CVE-2016-7103: Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
nvd