CVE-2019-2616
KEVlargeUnauthenticated Data Access and Tampering in Oracle BI Publisher (CVE-2019-2616)
CISA: Oracle BI Publisher Unauthorized Access Vulnerability
Oracle BI Publisher (formerly XML Publisher), a component of Oracle Fusion Middleware, contains an unauthorized-access flaw in its BI Publisher Security subcomponent affecting versions 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. An unauthenticated attacker with network access can trigger it by sending crafted HTTP requests to the BI Publisher service, with no credentials or user interaction required. Successful exploitation yields unauthorized read access to a subset of BI Publisher-accessible data and unauthorized update, insert or delete access to some of that data; because the CVSS scope is 'changed,' attacks may also significantly impact additional products that depend on the component. Any organization running the affected versions — including BI Publisher embedded in other Oracle Fusion Middleware deployments — is at risk. The flaw is confirmed exploited in the wild (CISA KEV, added 2022-03-25) and carries a very high EPSS (~92%), although no public proof-of-concept is known.
What to do: Apply the Oracle-provided patch per vendor instructions (this 2019 CVE was fixed in the April 2019 Oracle Critical Patch Update), updating any installation on 11.1.1.9.0, 12.2.1.3.0 or 12.2.1.4.0. As an interim mitigation, restrict HTTP access to BI Publisher interfaces to trusted networks only. Given the CISA KEV listing, prioritize patching internet-facing instances and review logs for signs of unauthorized reads or writes to BI Publisher data.
| Oracle BI Publisher (formerly XML Publisher), component of Oracle Fusion Middleware (subcomponent: BI Publisher Security) | 11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). While the vulnerability is in BI Publisher (formerly XML Publisher), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of BI Publisher (formerly XML Publisher) accessible data as well as unauthorized read access to a subset of BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).
- Affected
- Oracle BI Publisher (Formerly XML Publisher)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- oracle
- Products
- business intelligence publisher
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N