CVE-2024-21082
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 16, 2024
Updated: Apr 17, 2024
Summary
CVE-2024-21082 is a severe vulnerability affecting Oracle BI Publisher, a component of Oracle Analytics. Versions 7.0.0.0.0 and 12.2.1.4.0 are vulnerable to this easily exploitable issue. An unauthenticated attacker with network access via HTTP can leverage this vulnerability to compromise Oracle BI Publisher, leading to takeover. The impact on confidentiality, integrity, and availability is high, with a base score of 9.8 according to the CVSS 3.1 metric. The vector for this vulnerability is (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Oracle BI Publisher
Affected Vendors
- BonqDAO