CVE-2023-22105

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Oct 17, 2023
Updated: Oct 23, 2023

Summary

CVE-2023-22105 is a vulnerability in the BI Publisher product of Oracle Analytics, specifically affecting versions 6.4.0.0.0 and 7.0.0.0.0. This vulnerability can be easily exploited by a low privileged attacker with network access via HTTP, potentially compromising BI Publisher. Successful attacks may require human interaction from someone other than the attacker and can impact additional products beyond BI Publisher. The consequences of exploiting this vulnerability include unauthorized access to data in BI Publisher, including the ability to update, insert, or delete data, as well as unauthorized read access to a subset of data. The CVSS 3.1 Base Score for this vulnerability is 5.4, indicating moderate confidentiality and integrity impacts.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2023-22105 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options