Oracle Corporation Bi Publisher vulnerabilities
60 known vulnerabilities affecting oracle_corporation/bi_publisher.
Total CVEs
60
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
4
Severity breakdown
CRITICAL1HIGH46MEDIUM13
Vulnerabilities
Page 1 of 3
CVE-2019-2616P1HIGHCVSS 7.2KEVPoCv11.1.1.9.0v12.2.1.3.0+1 more2019-04-23
CVE-2019-2616 [HIGH] CVE-2019-2616: Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (su
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher).
nvd
CVE-2019-2588P2MEDIUMCVSS 4.9ExploitedPoCv11.1.1.9.0v12.2.1.3.0+1 more2019-04-23
CVE-2019-2588 [MEDIUM] CVE-2019-2588: Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (su
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher)
nvd
CVE-2019-2767P2HIGHCVSS 7.2ExploitedPoCv11.1.1.9.0v12.2.1.3.0+1 more2019-07-23
CVE-2019-2767 [HIGH] CVE-2019-2767: Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (su
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The supported version that is affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher)
nvd
CVE-2019-2768P2HIGHCVSS 7.5Exploitedv11.1.1.9.02019-07-23
CVE-2019-2768 [HIGH] CVE-2019-2768: Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (su
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The supported version that is affected is 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Successful attacks of this
nvd
CVE-2021-2400P2HIGHCVSS 7.5v5.5.0.0.0v11.1.1.9.0+2 more2021-07-21
CVE-2021-2400 [HIGH] CVE-2021-2400: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vul
nvd
CVE-2021-2396P2HIGHCVSS 8.8v5.5.0.0.0v11.1.1.9.0+2 more2021-07-21
CVE-2021-2396 [HIGH] CVE-2021-2396: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vuln
nvd
CVE-2021-2391P2HIGHCVSS 8.8v5.5.0.0.0v11.1.1.9.0+2 more2021-07-21
CVE-2021-2391 [HIGH] CVE-2021-2391: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Scheduler).
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Scheduler). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability ca
nvd
CVE-2021-2401P3MEDIUMCVSS 5.3v5.5.0.0.0v11.1.1.9.0+2 more2021-07-21
CVE-2021-2401 [MEDIUM] CWE-611 CVE-2021-2401: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks o
nvd
CVE-2024-21082P2CRITICALCVSS 9.8v7.0.0.0.0v12.2.1.4.02024-04-16
CVE-2024-21082 [CRITICAL] CWE-611 CVE-2024-21082: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Sup
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in tak
nvd
CVE-2021-2392P3HIGHCVSS 8.8v5.5.0.0.0v11.1.1.9.0+2 more2021-07-21
CVE-2021-2392 [HIGH] CVE-2021-2392: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publishe
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vuln
nvd
CVE-2023-21846P3HIGHCVSS 8.8v5.9.0.0.0v6.4.0.0.0+1 more2023-01-18
CVE-2023-21846 [HIGH] CWE-284 CVE-2023-21846: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security).
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 5.9.0.0.0, 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle BI Publisher. Successful attacks of this vulnera
nvd
CVE-2023-21832P3HIGHCVSS 8.8v5.9.0.0.0v6.4.0.0.0+1 more2023-01-18
CVE-2023-21832 [HIGH] CWE-284 CVE-2023-21832: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security).
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 5.9.0.0.0, 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle BI Publisher. Successful attacks of this vulnera
nvd
CVE-2020-14879P3HIGHCVSS 8.5v5.5.0.0.0v11.1.1.9.0+2 more2020-10-21
CVE-2020-14879 [HIGH] CVE-2020-14879: Vulnerability in the BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite -
Vulnerability in the BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher. While the vulnerability is in BI Publisher
nvd
CVE-2020-14880P3HIGHCVSS 8.5v5.5.0.0.0v11.1.1.9.0+2 more2020-10-21
CVE-2020-14880 [HIGH] CVE-2020-14880: Vulnerability in the BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite -
Vulnerability in the BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher. While the vulnerability is in BI Publisher
nvd
CVE-2022-21346P3HIGHCVSS 7.5v5.5.0.0.0v12.2.1.3.0+1 more2022-01-19
CVE-2022-21346 [HIGH] CVE-2022-21346: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publishe
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability
nvd
CVE-2018-2958P3HIGHCVSS 8.2v11.1.1.7.0v11.1.1.9.0+2 more2018-07-18
CVE-2018-2958 [HIGH] CVE-2018-2958: Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: BI Publisher
Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks of this vulnerabilit
nvd
CVE-2018-2900P3HIGHCVSS 8.2v11.1.1.7.02018-07-18
CVE-2018-2900 [HIGH] CVE-2018-2900: Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Layout Tools)
Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Layout Tools). The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks of this vulnerability can result in unauthorized creation, deletio
nvd
CVE-2017-10025P3HIGHCVSS 8.2v11.1.1.7.02017-08-08
CVE-2017-10025 [HIGH] CVE-2017-10025: Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: BI Publisher
Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks of this vulnerability can result in unauthorized access
nvd
CVE-2017-10037P3HIGHCVSS 7.5v11.1.1.7.0v11.1.1.9.02017-10-19
CVE-2017-10037 [HIGH] CWE-200 CVE-2017-10037: Vulnerability in the Oracle BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Se
Vulnerability in the Oracle BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Service API). Supported versions that are affected are 11.1.1.7.0 and 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can
nvd
CVE-2021-2050P3HIGHCVSS 7.6v5.5.0.0.0v11.1.1.9.0+2 more2021-01-20
CVE-2021-2050 [HIGH] CVE-2021-2050: Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vuln
nvd
1 / 3Next →