cbcvebase.

Oracle Business Intelligence Publisher vulnerabilities

39 known vulnerabilities affecting oracle/business_intelligence_publisher.

Total CVEs
39
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
HIGH32MEDIUM6LOW1

Vulnerabilities

Page 2 of 2
CVE-2017-10028P3HIGHCVSS 8.2v11.1.1.7.02017-08-08
CVE-2017-10028 [HIGH] CVE-2017-10028: Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Server). Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Server). The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human interaction from a person other than the attacker and
nvd
CVE-2017-10043P3HIGHCVSS 8.2v11.1.1.7.0v11.1.1.9.02017-08-08
CVE-2017-10043 [HIGH] CVE-2017-10043: Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: BI Publisher Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.7.0 and 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human interaction from a person ot
nvd
CVE-2017-10030P3HIGHCVSS 8.2v11.1.1.7.02017-08-08
CVE-2017-10030 [HIGH] CVE-2017-10030: Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Server). Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Server). The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human interaction from a person other than the attacker and
nvd
CVE-2020-14784P3HIGHCVSS 8.2v11.1.1.9.0v12.2.1.3.0+1 more2020-10-21
CVE-2020-14784 [HIGH] CVE-2020-14784: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Mobile Serv Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Mobile Service). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interaction f
nvd
CVE-2020-14842P3HIGHCVSS 8.2v5.5.0.0.0v11.1.1.9.0+2 more2020-10-21
CVE-2020-14842 [HIGH] CVE-2020-14842: Vulnerability in the BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Secur Vulnerability in the BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human interacti
nvd
CVE-2019-2595P3HIGHCVSS 8.2v11.1.1.9.0v12.2.1.3.0+1 more2019-04-23
CVE-2019-2595 [HIGH] CVE-2019-2595: Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (su Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher).
nvd
CVE-2021-2062P3HIGHCVSS 7.6v5.5.0.0.0v11.1.1.9.0+2 more2021-01-20
CVE-2021-2062 [HIGH] CVE-2021-2062: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Web Server) Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Web Server). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interacti
nvd
CVE-2020-14696P3HIGHCVSS 7.2v11.1.1.9.0v12.2.1.3.0+1 more2020-07-15
CVE-2020-14696 [HIGH] CVE-2020-14696: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Layout Temp Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Layout Templates). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publ
nvd
CVE-2017-10041P3HIGHCVSS 7.6v11.1.1.9.0v12.2.1.1.0+1 more2017-08-08
CVE-2017-10041 [HIGH] CVE-2017-10041: Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Server). Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Server). Supported versions that are affected are 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human interaction from a person ot
nvd
CVE-2019-2601P3HIGHCVSS 7.6v11.1.1.9.0v12.2.1.3.0+1 more2019-04-23
CVE-2019-2601 [HIGH] CVE-2019-2601: Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (su Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). S
nvd
CVE-2019-2742P3HIGHCVSS 7.2v11.1.1.9.02019-07-23
CVE-2019-2742 [HIGH] CVE-2019-2742: Vulnerability in the Oracle BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Se Vulnerability in the Oracle BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Service API). The supported version that is affected is 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may signi
nvd
CVE-2018-2925P3MEDIUMCVSS 6.5v11.1.1.7.0v11.1.1.9.0+2 more2018-07-18
CVE-2018-2925 [MEDIUM] CVE-2018-2925: Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Server). Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Server). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher. Successful attacks of this vulnerability can resu
nvd
CVE-2017-10059P3HIGHCVSS 7.6v11.1.1.7.02017-08-08
CVE-2017-10059 [HIGH] CVE-2017-10059: Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Mobile Servic Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Mobile Service). The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human interaction from a person other than the attacker
nvd
CVE-2017-10157P3MEDIUMCVSS 6.5v11.1.1.7.0v11.1.1.9.0+2 more2017-08-08
CVE-2017-10157 [MEDIUM] CVE-2017-10157: Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: BI Publisher Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks of this vulnerab
nvd
CVE-2020-14780P3HIGHCVSS 7.1v5.5.0.0.0v11.1.1.9.0+2 more2020-10-21
CVE-2020-14780 [HIGH] CVE-2020-14780: Vulnerability in the BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Secur Vulnerability in the BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human interacti
nvd
CVE-2024-20980P4MEDIUMCVSS 5.4v6.4.0.0.0v7.0.0.0.02024-02-17
CVE-2024-20980 [MEDIUM] CVE-2024-20980: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Suppo Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 6.4.0.0.0 and 7.0.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interaction from a person other than th
nvd
CVE-2016-3432P4MEDIUMCVSS 5.4v11.1.1.7.0v11.1.1.9.02016-07-21
CVE-2016-3432 [MEDIUM] CVE-2016-3432: Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Mi Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0 and 11.1.1.9.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to Web Server.
nvd
CVE-2016-0614P4MEDIUMCVSS 4.0v11.1.1.7.0v11.1.1.9.0+1 more2016-01-21
CVE-2016-0614 [MEDIUM] CVE-2016-0614: Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 11.1.1.7. Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote authenticated users to affect confidentiality via unknown vectors.
nvd
CVE-2016-3474P4LOWCVSS 3.7v11.1.1.7.0v11.1.1.9.0+1 more2016-07-21
CVE-2016-3474 [LOW] CVE-2016-3474: Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Mi Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote attackers to affect confidentiality via vectors related to Security.
nvd