{ "id": "CVE-2020-14879", "sourceIdentifier": "secalert_us@oracle.com", "published": "2020-10-21T15:15:25.157", "lastModified": "2020-10-23T21:02:48.947", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "Vulnerability in the BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher. While the vulnerability is in BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher accessible data as well as unauthorized update, insert or delete access to some of BI Publisher accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N)." }, { "lang": "es", "value": "Vulnerabilidad en el producto BI Publisher de Oracle Fusion Middleware (componente: E-Business Suite - XDO). Las versiones compatibles que est\u00e1n afectadas son 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 y 12.2.1.4.0. Una vulnerabilidad explotable f\u00e1cilmente permite a un atacante poco privilegiado con acceso a la red por medio de HTTP comprometer a BI Publisher. Aunque la vulnerabilidad est\u00e1 en BI Publisher, los ataques pueden impactar significativamente a productos adicionales. Los ataques con \u00e9xito de esta vulnerabilidad pueden resultar en un acceso no autorizado a datos cr\u00edticos o acceso completo a todos los datos accesibles de BI Publisher, as\u00ed como tambi\u00e9n en una actualizaci\u00f3n no autorizada, insertar o eliminar el acceso a algunos de los datos accesibles de BI Publisher. CVSS 3.1 Puntuaci\u00f3n Base 8.5 (Impactos de la Confidencialidad e Integridad). Vector CVSS: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N)" } ], "metrics": { "cvssMetricV31": [ { "source": "secalert_us@oracle.com", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "CHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "LOW", "availabilityImpact": "NONE", "baseScore": 8.5, "baseSeverity": "HIGH" }, "exploitabilityScore": 3.1, "impactScore": 4.7 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:S/C:C/I:P/A:N", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "SINGLE", "confidentialityImpact": "COMPLETE", "integrityImpact": "PARTIAL", "availabilityImpact": "NONE", "baseScore": 7.5 }, "baseSeverity": "HIGH", "exploitabilityScore": 8.0, "impactScore": 7.8, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-noinfo" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:oracle:business_intelligence_publisher:5.5.0.0.0:*:*:*:*:*:*:*", "matchCriteriaId": "F8E79D52-33E2-4305-A9F5-A4C88C0FF120" }, { "vulnerable": true, "criteria": "cpe:2.3:a:oracle:business_intelligence_publisher:11.1.1.9.0:*:*:*:*:*:*:*", "matchCriteriaId": "94BF6E68-C7FA-4D38-970B-88F37DA7BCCA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:oracle:business_intelligence_publisher:12.2.1.3.0:*:*:*:*:*:*:*", "matchCriteriaId": "E9430793-49B0-4D74-A3D8-6518A26D2475" }, { "vulnerable": true, "criteria": "cpe:2.3:a:oracle:business_intelligence_publisher:12.2.1.4.0:*:*:*:*:*:*:*", "matchCriteriaId": "542158AD-09AC-4132-A1CA-ACE671CCA1FD" } ] } ] } ], "references": [ { "url": "https://www.oracle.com/security-alerts/cpuoct2020.html", "source": "secalert_us@oracle.com", "tags": [ "Vendor Advisory" ] } ] }