CVE-2024-21195

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Oct 15, 2024

Summary

CVE-2024-21195 is a vulnerability found in the Oracle BI Publisher component of Oracle Analytics, affecting versions 7.0.0.0.0, 7.6.0.0.0, and 12.2.1.4.0. This easily exploitable vulnerability permits a low-privileged attacker with network access via HTTP to gain unauthorized access to sensitive data and perform actions such as data updates, inserts, or deletions within Oracle BI Publisher, potentially leading to partial denial of service conditions. The CVSS 3.1 Base Score for this vulnerability is 7.6, indicating high severity with significant impacts on confidentiality and integrity while posing a low impact on availability. To remediate this issue, organizations should apply the necessary patches provided by Oracle as outlined in their security alerts (https://www.oracle.com/security-alerts/cpuoct2024.html). Failure to address this vulnerability could result in critical data exposure and operational disruptions for affected organizations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share