CVE-2016-3473

HIGH

Oracle BI Publisher - Info Disclosure

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote authenticated users to affect confidentiality via unknown vectors.

Exploits (1)

exploitdb WORKING POC
by Jakub Palaczynski · textwebappsxml
https://www.exploit-db.com/exploits/40590

References (4)

Core 4
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/40590/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/93719
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037051

Scores

CVSS v3 7.7
EPSS 0.0280
EPSS Percentile 86.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (3)
oracle/business_intelligence_publisher 11.1.1.7.0
oracle/business_intelligence_publisher 11.1.1.9.0
oracle/business_intelligence_publisher 12.2.1.0.0
Published Oct 25, 2016
Tracked Since Feb 18, 2026