PT-2023-2667 · Oracle · Oracle Bi Publisher
Khanh Nguyen Duy Quoc
·
Publicado
2023-04-18
·
Atualizado
2023-04-19
·
CVE-2023-21970
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle BI Publisher version 6.4.0.0.0
Description
The issue exists due to insufficient input validation in the Security component of Oracle BI Publisher. This allows a remote attacker to disclose sensitive information using HTTP requests. Successful attacks require human interaction and can result in unauthorized access to critical data or complete access to all accessible data.
Recommendations
For Oracle BI Publisher version 6.4.0.0.0, update to a version that addresses the insufficient input validation issue in the Security component to prevent unauthorized access to sensitive information.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Oracle Bi Publisher