CVE-2019-2767
BI Publisher Component of Oracle Fusion Middleware Unauthorized Update, Insert or Delete Vulnerability
Record summary
CVE-2019-2767 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.
Description
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The supported version that is affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). While the vulnerability is in BI Publisher (formerly XML Publisher), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of BI Publisher (formerly XML Publisher) accessible data as well as unauthorized read access to a subset of BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 19, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 15, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
BI PublisherBrowse Oracle / BI Publisher | VulnCheck | Version data not supplied | |
BI Publisher (formerly XML Publisher)Browse Oracle Corporation / BI Publisher (formerly XML Publisher) | CVE List | 11.1.1.9.0 | affected |
| 12.2.1.3.0 | affected | ||
| 12.2.1.4.0 | affected | ||
Nuclei templates
1ProjectDiscoveryHIGHOracle Business Intelligence Publisher - XML External Entity InjectionCVSS 7.2
Oracle Business Intelligence Publisher is vulnerable to an XML external entity injection attack. The supported versions affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. This easily exploitable vulnerability allows unauthenticated attackers with network access via HTTP to compromise BI Publisher.
Impact
An attacker can exploit this vulnerability to gain unauthorized access to sensitive information or disrupt the availability of the system.
Remediation
Apply the latest security patches provided by Oracle to fix this vulnerability.
Source: ProjectDiscovery