PT-2025-42976 · Oracle · Oracle Analytics+1
Published
2025-10-21
·
Updated
2025-10-22
·
CVE-2025-61754
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle BI Publisher versions 7.6.0.0.0 through 8.2.0.0.0
Description
An easily exploitable issue exists in the Web Service API component of Oracle BI Publisher within Oracle Analytics. A low-privileged attacker with network access via HTTP can compromise the application. Successful exploitation may lead to unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data.
Recommendations
Update to a version later than 8.2.0.0.0.
Update to a version later than 7.6.0.0.0.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Analytics
Oracle Bi Publisher