S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-2616 Scanner

CVE-2019-2616 scanner - XML External Entity (XXE) vulnerability in BI Publisher (formerly XML Publisher)

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2019-2616
7.2
CVSShigh
Exploitable remotely over the internet · no authentication required.

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). While the vulnerability is in BI Publisher (formerly XML Publisher), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of BI Publisher (formerly XML Publisher) accessible data as well as unauthorized read access to a subset of BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
BI Publisher (formerly XML Publisher)by Oracle Corporation
11.1.1.9.0
Updated Aug 21, 2026View on NVD →
Detail

BI Publisher (formerly XML Publisher) is a component of Oracle Fusion Middleware that is used for creating reports and documents for various business needs. Its primary purpose is to enable organizations to process, format, and deliver documents such as invoices, financial statements, and sales reports in a timely and efficient manner. BI Publisher has become a popular tool due to its flexibility, ease of use, and ability to integrate with different data sources.

However, a major vulnerability has been identified in BI Publisher (formerly XML Publisher) that could compromise an organization's sensitive data. The vulnerability code is CVE-2019-2616 and affects supported versions 11.1.1.9.0, 12.2.1.3.0, and 12.2.1.4.0. This vulnerability can be easily exploited by an unauthenticated attacker with network access via HTTP. Once exploited, unauthorized access to BI Publisher (formerly XML Publisher) accessible data could be granted resulting in unauthorized update, insert, or delete access as well as unauthorized read access to a subset of the same data.

The consequences of a successful attack of CVE-2019-2616 could lead to significant financial loss and damage to an organization's reputation. Sensitive data could be compromised, resulting in the loss of confidential information, financial records, and other critical data. Furthermore, regulatory compliance requirements could be compromised, leading to severe legal implications.

With the s4e.io platform's advanced features, those who read this article can quickly and easily identify vulnerabilities in their digital assets. Our platform is designed to provide organizations with real-time information on vulnerabilities and emerging threats, allowing them to stay ahead of the curve. With constant monitoring and real-time alerts, s4e.io provides organizations with a comprehensive and effective cybersecurity solution. By subscribing to our platform, businesses can take proactive steps towards protecting their sensitive data and operations from vulnerabilities such as CVE-2019-2616.

 

REFERENCES

Solution Advice

Organizations must take immediate precautions to protect themselves against the vulnerability CVE-2019-2616. Here is a bullet list of precautions that can be taken:

  • Apply the necessary patches to your BI Publisher (formerly XML Publisher) system
  • Restrict network access to BI Publisher (formerly XML Publisher) systems to authorized users only
  • Monitor your BI Publisher (formerly XML Publisher) environment for unusual activity
  • Implement multi-factor authentication to restrict unauthorized access
  • Train staff and employees on safe and secure practices to avoid attacks

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-2616 scanner - XML External Entity (XXE) vulnerability in BI Publisher (formerly XML Publisher) | S4E