CVE-2017-10157
Description
Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of BI Publisher accessible data as well as unauthorized read access to a subset of BI Publisher accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
Risk Information
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple vulnerabilities are affected in Oracle BI Publisher 11.1.1.7.0 | Windows |
| Vulnerabilities CVE-2015-5254,CVE-2016-3092,CVE-2017-10041,CVE-2017-10156,CVE-2017-10157 are affected in Oracle BI Publisher 12.2.1.1.0 | Windows |
| Multiple vulnerabilities are affected in Oracle BI Publisher 12.2.1.2.0 | Windows |
| Multiple vulnerabilities are affected in Oracle BI Publisher 11.1.1.9.0 | Windows |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234