PT-2021-1720 · Oracle · Oracle Bi Publisher

Bui Duong

·

Published

2021-01-19

·

Updated

2021-01-26

·

CVE-2021-2050

CVSS v2.0

8.0

High

VectorAV:N/AC:L/Au:S/C:C/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Oracle BI Publisher versions 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0
Description: The issue is related to inadequate access control in the Oracle BI Publisher product, allowing a low-privileged attacker with network access via HTTP to compromise the system. Successful attacks can result in unauthorized access to critical data, including read, modify, insert, or delete access to some data, as well as partial denial of service.
Recommendations: For versions 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0, and 12.2.1.4.0, at the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00410
CVE-2021-2050

Affected Products

Oracle Bi Publisher