CVE-2025-50060
8.1Oracle · BI Publisher
A vulnerability in the Oracle BI Publisher Web Server component allows a low-privileged attacker with network access to gain unauthorized read and write access to critical data.
Executive summary
Oracle BI Publisher is vulnerable to unauthorized data access and modification due to a flaw in the Web Server component that can be leveraged by low-privileged authenticated attackers.
Vulnerability
The vulnerability exists within the Web Server component of Oracle BI Publisher. It allows an attacker with low-level privileges and network access via HTTP to perform unauthorized operations, including the creation, deletion, or modification of critical data.
Business impact
The impact of this vulnerability is significant, as it permits unauthorized access to, and manipulation of, sensitive business data stored within the BI Publisher environment. Given the high CVSS score of 8.1, this flaw poses a substantial threat to data confidentiality and integrity, potentially leading to unauthorized disclosure of proprietary information or the destruction of critical records.
Remediation
Immediate Action: Review the July 2025 Oracle Critical Patch Update advisory and apply the necessary security patches to the affected BI Publisher versions as soon as they become available.
Proactive Monitoring: Monitor Web Server access logs for anomalous HTTP requests or unusual patterns originating from low-privileged user accounts that deviate from established operational baselines.
Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall (WAF) to filter and block suspicious HTTP traffic targeting the BI Publisher web interface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a high-risk exposure for organizations relying on Oracle BI Publisher for sensitive data management. It is imperative that security teams prioritize the identification of affected systems and prepare to apply vendor-supplied patches immediately upon release to prevent unauthorized data manipulation or theft.
More Oracle CVEs all →
History
- Disclosed CVE record published
- Published in the daily brief high section
- Published in the daily brief high section
- Analyst report written
Sources
- Oracle Advisory Vendor advisory