CVE-2024-21084: Medium severity oracle analytics publisher vulnerability
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Service Gateway). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 5.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21084?
CVE-2024-21084 is classified as an easily exploitable vulnerability that allows unauthenticated attackers to compromise Oracle BI Publisher.
How do I fix CVE-2024-21084?
To mitigate CVE-2024-21084, update Oracle BI Publisher to the latest supported version provided by Oracle.
Who is affected by CVE-2024-21084?
CVE-2024-21084 affects Oracle BI Publisher versions 7.0.0.0.0 and 12.2.1.4.0.
What type of attack does CVE-2024-21084 permit?
CVE-2024-21084 allows an unauthenticated attacker with HTTP network access to compromise the Oracle BI Publisher.
Is authentication required to exploit CVE-2024-21084?
No, CVE-2024-21084 can be exploited without any authentication.