EXPOSURES › CVE-2019-2616
CVE-2019-2616
HIGH ⌖ ON CISA KEV · EXPLOITEDOracle BI Publisher had an authentication bypass vulnerability that allowed unauthorized access.
Oracle BI Publisher contained an authentication bypass vulnerability enabling unauthorized access to the system. This failure is critical for DIB organizations because it directly compromises data confidentiality and violates access control requirements under NIST 800-171. Organizations must ensure all Oracle BI Publisher instances are patched and access controls are rigorously enforced to prevent similar breaches.
Shame score — The vulnerability allowed authentication bypass, enabling unauthorized access to sensitive data, which is a severe compliance and security failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |