PT-2023-2667 · Oracle · Oracle Bi Publisher

Khanh Nguyen Duy Quoc

·

Published

2023-04-18

·

Updated

2023-04-19

·

CVE-2023-21970

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle BI Publisher version 6.4.0.0.0
Description The issue exists due to insufficient input validation in the Security component of Oracle BI Publisher. This allows a remote attacker to disclose sensitive information using HTTP requests. Successful attacks require human interaction and can result in unauthorized access to critical data or complete access to all accessible data.
Recommendations For Oracle BI Publisher version 6.4.0.0.0, update to a version that addresses the insufficient input validation issue in the Security component to prevent unauthorized access to sensitive information.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2023-02507
CVE-2023-21970

Affected Products

Oracle Bi Publisher