First published: Tue Apr 16 2024(Updated: )
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Script Engine). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle BI Publisher | =7.0.0.0.0 | |
Oracle BI Publisher | =12.2.1.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21083 is classified as a high severity vulnerability that can be easily exploited by high privileged attackers.
To fix CVE-2024-21083, users should apply the latest security patches provided by Oracle for the affected versions.
CVE-2024-21083 affects Oracle BI Publisher versions 7.0.0.0.0 and 12.2.1.4.0.
Yes, CVE-2024-21083 could allow attackers with network access via HTTP to compromise Oracle BI Publisher.
CVE-2024-21083 involves a vulnerability in the Script Engine component of Oracle BI Publisher.