Junglewise Threat Intelligence

CVE-2019-2616: Oracle BI Publisher Unauthorized Access Vulnerability

CVE-2019-2616 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2022-03-25

Vendors: Oracle.

Executive brief

A vulnerability in the BI Publisher Security subcomponent of Oracle Fusion Middleware allows unauthenticated attackers with network access via HTTP to compromise the system. Successful exploitation can lead to unauthorized read, update, insert, or delete access to a subset of BI Publisher data and may impact additional products.

Affected products

  • Oracle BI Publisher (formerly XML Publisher) 11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0

Timeline

  • 2019-04-23: disclosed: NVD Published Date
  • 2022-03-25: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog