Vulnerabilities > Oracle > Business Intelligence > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-01-02 CVE-2019-14862 Cross-site Scripting vulnerability in multiple products
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
network
low complexity
knockoutjs redhat oracle CWE-79
6.1
2019-11-08 CVE-2019-10219 Cross-site Scripting vulnerability in multiple products
A vulnerability was found in Hibernate-Validator.
network
low complexity
redhat netapp oracle CWE-79
6.1
2019-10-16 CVE-2019-3012 Unspecified vulnerability in Oracle Business Intelligence 11.1.1.9.0/12.2.1.3.0/12.2.1.4.0
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: BI Platform Security).
network
low complexity
oracle
5.3
2019-10-16 CVE-2019-2897 Unspecified vulnerability in Oracle products
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions).
network
low complexity
oracle
6.4
2019-02-27 CVE-2019-1559 Information Exposure Through Discrepancy vulnerability in multiple products
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC.
5.9
2018-01-18 CVE-2018-2715 Unspecified vulnerability in Oracle Business Intelligence 12.2.1.2.0/12.2.1.3.0
Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: BI Platform Security).
network
low complexity
oracle
6.5
2017-10-19 CVE-2017-10163 Unspecified vulnerability in Oracle Business Intelligence
Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Web General).
network
low complexity
oracle
6.3
2017-08-08 CVE-2017-10058 Unspecified vulnerability in Oracle Business Intelligence 11.1.1.9.0/12.2.1.1.0/12.2.1.2.0
Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Web Administration).
network
low complexity
oracle
6.9
2017-03-15 CVE-2016-7103 Cross-site Scripting vulnerability in multiple products
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
6.1
2016-07-21 CVE-2016-3433 Unspecified vulnerability in Oracle Business Intelligence 11.1.1.7.0/11.1.1.9.0
Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 11.1.1.7.0 and 11.1.1.9.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to Analytics Web Administration.
network
low complexity
oracle
5.4