Improper input validation in Oracle BI Publisher - CVE-2023-30535
Published: July 19, 2023
Vulnerability identifier: #VU78400
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-30535
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to improper input validation within the Development Operations (Snowflake JDBC) component in BI Publisher. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.
Affected software
Oracle BI Publisher
Oracle Business Intelligence Enterprise Edition
IBM Security Guardium
Oracle GoldenGate Big Data
Oracle Business Intelligence Enterprise Edition
IBM Security Guardium
Oracle GoldenGate Big Data
How to mitigate CVE-2023-30535
Install updates from vendor's website.
IBM Security Guardium - update to 11.5
Oracle GoldenGate Big Data - update to 21.2
Oracle GoldenGate Big Data - update to 21.2