Improper input validation in Oracle BI Publisher - CVE-2024-43382

 

Improper input validation in Oracle BI Publisher - CVE-2024-43382

Published: January 21, 2025


Vulnerability identifier: #VU103153
CSH Severity: Medium
CVSS v4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-43382
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote privileged user to read and manipulate data.

The vulnerability exists due to improper input validation within the XML Services (Snowflake JDBC) component in Oracle BI Publisher. A remote privileged user can exploit this vulnerability to read and manipulate data.


Affected software

Oracle BI Publisher
IBM Cloud Pak for Watson AIOps
Guardium Data Protection
IBM Observability with Instana
watsonx.data

How to mitigate CVE-2024-43382

Install updates from vendor's website.

IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM Observability with Instana - update to 286
watsonx.data - update to 2.1.1
Guardium Data Protection - update to 12.0p35

External References

Related Security Bulletins