Vulnerabilities fixed in Oracle Analytics (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- Oracle BI Publisher and Oracle Business Intelligence Enterprise Edition affected
- Full system compromise by unauthenticated attackers via HTTP
- Low-privileged attackers can bypass authentication via Web Service API
"Oracle has fixed multiple vulnerabilities in Oracle BI Publisher and Oracle Business Intelligence Enterprise Edition. Unauthenticated attackers can achieve full system compromise, authentication bypass, arbitrary code execution, denial of service, and unauthorized data operations via HTTP. Low-privileged attackers can bypass authentication controls via the Web Service API."
no comments yet.