oracle bi-publisher CVE-2019-2898 is a vulnerability in Oracle Bi Publisher
Published on October 16, 2019

Vulnerability in the BI Publisher (formerly XML Publisher) product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Successful attacks of this vulnerability can result in unauthorized read access to a subset of BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

NVD


Products Associated with CVE-2019-2898

Want to know whenever a new CVE is published for Oracle Bi Publisher? stack.watch will email you.

 

Affected Versions

Oracle Corporation BI Publisher (formerly XML Publisher):

Exploit Probability

EPSS
0.30%
Percentile
53.12%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.