S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-2767 Scanner

Detects 'XML External Entity (XXE)' vulnerability in Oracle Corporation BI Publisher (formerly XML Publisher) affects v. 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-2767
7.2
CVSS

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The supported version that is affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). While the vulnerability is in BI Publisher (formerly XML Publisher), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of BI Publisher (formerly XML Publisher) accessible data as well as unauthorized read access to a subset of BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
BI Publisher (formerly XML Publisher)by Oracle Corporation
11.1.1.9.0
Updated Aug 21, 2026View on NVD →
Detail

Oracle Corporation's BI Publisher (formerly XML Publisher) is a powerful tool used for creating and managing business intelligence documents, such as reports, invoices, and statements. It is commonly utilized by businesses and organizations around the world to manage and streamline their financial and operational processes. With the ability to integrate with various data sources and output formats, BI Publisher allows users to easily generate and distribute custom reports and documents according to their specific needs.

However, a recently discovered vulnerability, CVE-2019-2767, has been detected in BI Publisher that may compromise the security of sensitive business data. This vulnerability can be easily exploited by an unauthenticated attacker with network access via HTTP, allowing them to gain unauthorized access to BI Publisher's accessible data. The vulnerability affects versions 11.1.1.9.0, 12.2.1.3.0, and 12.2.1.4.0 of BI Publisher.

If exploited, the CVE-2019-2767 vulnerability can lead to unauthorized update, insert, or delete access to BI Publisher's accessible data, as well as unauthorized read access to a subset of its data. This means that sensitive financial and operational information may be compromised, leading to severe consequences for businesses and organizations that rely on BI Publisher for their reporting needs. The CVSS 3.0 Base Score for this vulnerability is 7.2, with impacts on confidentiality and integrity.

Thanks to the pro features of the s4e.io platform, businesses and organizations can easily stay informed of vulnerabilities in their digital assets. The platform provides comprehensive vulnerability scanning and threat intelligence services, allowing users to detect and mitigate security risks before they can cause serious harm. By taking advantage of this powerful tool, businesses and organizations can ensure the safety and security of their critical data.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Ensure that all BI Publisher components are up to date with the latest security patches and updates.
  • Implement strict access controls and restrict network access to BI Publisher as much as possible.
  • Monitor network traffic for any suspicious activity related to BI Publisher.
  • Consider using additional security tools, such as firewalls or intrusion detection systems, to detect and prevent unauthorized access to BI Publisher.
  • Educate employees about the risks associated with this vulnerability and provide training on safe internet practices.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-2767 scanner - XML External Entity (XXE) vulnerability in Oracle Corporation BI Publisher (formerly XML Publisher) | S4E