nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-61754 CVE-2025-61754
MEDIUM
Record summary
CVE-2025-61754 has a selected CVSS score of 6.5 (medium).
Description
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 7.6.0.0.0 and 8.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Description source: GitHub Advisory
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 22, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Oracle BI PublisherBrowse Oracle Corporation / Oracle BI Publisher | CVE List | 7.6.0.0.0 | affected |
| 8.2.0.0.0 | affected |
References
2Oracle AdvisoryVendor advisory
https://www.oracle.com/security-alerts/cpuoct2025.html