PT-2023-2667 · Oracle · Oracle Bi Publisher
Khanh Nguyen Duy Quoc
·
Published
2023-04-18
·
Updated
2023-04-19
·
CVE-2023-21970
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle BI Publisher version 6.4.0.0.0
Description
The issue exists due to insufficient input validation in the Security component of Oracle BI Publisher. This allows a remote attacker to disclose sensitive information using HTTP requests. Successful attacks require human interaction and can result in unauthorized access to critical data or complete access to all accessible data.
Recommendations
For Oracle BI Publisher version 6.4.0.0.0, update to a version that addresses the insufficient input validation issue in the Security component to prevent unauthorized access to sensitive information.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Bi Publisher