CVE-2019-2767 is a high-severity vulnerability in Oracle BI Publisher (formerly XML Publisher) affecting versions 11.1.1.9.0, 12.2.1.3.0, and 12.2.1.4.0. This easily exploitable flaw allows unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks can lead to unauthorized modification or deletion of some accessible data, as well as unauthorized read access to a subset of data, with a CVSS 3.0 Base Score of 7.2. While there is no evidence of active exploitation or public exploit code like Metasploit or ExploitDB, a Nuclei template for XML External Entity Injection exists, indicating potential for exploitation. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.1.1.9.0CPE matchmatch criteria | cpe:2.3:a:oracle:bi_publisher:11.1.1.9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.