S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-2588 Scanner

CVE-2019-2588 scanner - Path Traversal vulnerability in Oracle BI Publisher (formerly XML Publisher)

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-2588
4.9
CVSS

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
BI Publisher (formerly XML Publisher)by Oracle Corporation
11.1.1.9.0
Updated Aug 21, 2026View on NVD →
Detail

Oracle BI Publisher (formerly known as XML Publisher) is an enterprise-level tool designed to generate and deliver documents, reports, and correspondence. This tool provides a scalable and efficient solution that simplifies the creation and dissemination of complex document arrangements with high-quality layout and structure. BI Publisher is commonly used with a variety of business systems, including Oracle ERPs, as well as with other non-Oracle applications. The tool can be implemented on-premises, as well as in cloud infrastructures.

CVE-2019-2588 is a vulnerability that can be exploited in the BI Publisher Security subcomponent of Oracle Fusion Middleware. This critical vulnerability affects versions 11.1.1.9.0, 12.2.1.3.0, and 12.2.1.4.0. It enables highly privileged attackers with network access through the use of HTTP to compromise the BI Publisher. Malicious or unauthorized users with access to these versions can exploit this vulnerability to access critical data and gain complete control over the BI Publisher, which can lead to further unauthorized access to systems and data across the enterprise.

When exploited, this vulnerability can result in unauthorized access to critical data, complete access to all BI Publisher accessible data, and an increased risk of hacking. Attackers can use this vulnerability to compromise systems, install malware, or steal valuable intellectual property for malicious purposes. As a result, this vulnerability poses a significant threat to BI Publisher users, as well as to their larger enterprise database and cloud infrastructure.

Thanks to s4e.io, those concerned about vulnerabilities in their digital assets can quickly and easily learn about potential threats to their systems. With the help of pro features available on this platform, anyone can receive timely and accurate notification of potential vulnerabilities, as well as access to up-to-date mitigation strategies and best practices. By taking proactive measures to secure their BI Publisher against known vulnerabilities, users can better protect against hackers and other malicious threats.

 

REFERENCES

Solution Advice

Preventing this vulnerability from being exploited requires a proactive and comprehensive approach that includes several precautions, including:

  • Patching systems with the necessary security update
  • Limiting network access to the BI Publisher
  • Enabling and enforcing strong authentication protocols
  • Ensuring all applications and services that integrate with BI Publisher are updated with the latest security patches
  • Regularly scanning BI Publisher for potential vulnerabilities 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-2588 scanner - Path Traversal vulnerability in Oracle BI Publisher (formerly XML Publisher) | S4E