CVE-2024-21083: High severity oracle analytics publisher vulnerability
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Script Engine). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21083?
CVE-2024-21083 is classified as a high severity vulnerability that can be easily exploited by high privileged attackers.
How do I fix CVE-2024-21083?
To fix CVE-2024-21083, users should apply the latest security patches provided by Oracle for the affected versions.
Which versions are affected by CVE-2024-21083?
CVE-2024-21083 affects Oracle BI Publisher versions 7.0.0.0.0 and 12.2.1.4.0.
Are there any exploit scenarios for CVE-2024-21083?
Yes, CVE-2024-21083 could allow attackers with network access via HTTP to compromise Oracle BI Publisher.
What component of Oracle Analytics is involved in CVE-2024-21083?
CVE-2024-21083 involves a vulnerability in the Script Engine component of Oracle BI Publisher.