Skip to content
COOEY

EXPOSURES › CVE-2019-2616

CVE-2019-2616

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-2616 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildauth-bypassunpatched

Oracle BI Publisher had an authentication bypass vulnerability that allowed unauthorized access.

Oracle BI Publisher contained an authentication bypass vulnerability enabling unauthorized access to the system. This failure is critical for DIB organizations because it directly compromises data confidentiality and violates access control requirements under NIST 800-171. Organizations must ensure all Oracle BI Publisher instances are patched and access controls are rigorously enforced to prevent similar breaches.

Shame score — The vulnerability allowed authentication bypass, enabling unauthorized access to sensitive data, which is a severe compliance and security failure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass.

AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized