Improper input validation in Oracle Business Intelligence Enterprise Edition - CVE-2019-2897
Published: June 5, 2020
Vulnerability identifier: #VU28672
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-2897
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated user to read and manipulate data.
The vulnerability exists due to improper input validation within the Analytics Actions component in Oracle Business Intelligence Enterprise Edition. A remote authenticated user can exploit this vulnerability to read and manipulate data.
Affected software
Oracle Business Intelligence Enterprise Edition
Enterprise Manager Base Platform
Enterprise Manager Base Platform
How to mitigate CVE-2019-2897
Install updates from vendor's website.