Improper input validation in Oracle BI Publisher - CVE-2023-30535

 

Improper input validation in Oracle BI Publisher - CVE-2023-30535

Published: July 19, 2023


Vulnerability identifier: #VU78400
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-30535
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The vulnerability exists due to improper input validation within the Development Operations (Snowflake JDBC) component in BI Publisher. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.


Affected software

Oracle BI Publisher
Oracle Business Intelligence Enterprise Edition
IBM Security Guardium
Oracle GoldenGate Big Data

How to mitigate CVE-2023-30535

Install updates from vendor's website.

IBM Security Guardium - update to 11.5
Oracle GoldenGate Big Data - update to 21.2

External References

Related Security Bulletins