ZeroHour

CVE-2019-2616

KEVlarge

Unauthenticated Data Access and Tampering in Oracle BI Publisher (CVE-2019-2616)

CISA: Oracle BI Publisher Unauthorized Access Vulnerability

CVSS 3.1
7.2 high
EPSS
92%p100
Published
()
KEV added
AI analysis

Oracle BI Publisher (formerly XML Publisher), a component of Oracle Fusion Middleware, contains an unauthorized-access flaw in its BI Publisher Security subcomponent affecting versions 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. An unauthenticated attacker with network access can trigger it by sending crafted HTTP requests to the BI Publisher service, with no credentials or user interaction required. Successful exploitation yields unauthorized read access to a subset of BI Publisher-accessible data and unauthorized update, insert or delete access to some of that data; because the CVSS scope is 'changed,' attacks may also significantly impact additional products that depend on the component. Any organization running the affected versions — including BI Publisher embedded in other Oracle Fusion Middleware deployments — is at risk. The flaw is confirmed exploited in the wild (CISA KEV, added 2022-03-25) and carries a very high EPSS (~92%), although no public proof-of-concept is known.

What to do: Apply the Oracle-provided patch per vendor instructions (this 2019 CVE was fixed in the April 2019 Oracle Critical Patch Update), updating any installation on 11.1.1.9.0, 12.2.1.3.0 or 12.2.1.4.0. As an interim mitigation, restrict HTTP access to BI Publisher interfaces to trusted networks only. Given the CISA KEV listing, prioritize patching internet-facing instances and review logs for signs of unauthorized reads or writes to BI Publisher data.

Affected
Oracle BI Publisher (formerly XML Publisher), component of Oracle Fusion Middleware (subcomponent: BI Publisher Security)11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0
Estimated exposure
largetens of thousands of deployments (order-of-magnitude estimate), likely thousands directly exposed on the internet — No counts appear in the source data; this is estimated from BI Publisher's ubiquity — it ships inside Oracle Fusion Middleware and ERP/BI products such as Oracle E-Business Suite and PeopleSoft — together with public internet scans that…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). While the vulnerability is in BI Publisher (formerly XML Publisher), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of BI Publisher (formerly XML Publisher) accessible data as well as unauthorized read access to a subset of BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).

CISA Known Exploited Vulnerability
Affected
Oracle BI Publisher (Formerly XML Publisher)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
oracle
Products
business intelligence publisher
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

In the news