CVE-2023-22012 is a low-privileged vulnerability affecting Oracle Business Intelligence Enterprise Edition (Analytics Server component, version 7.0.0.0.0). This easily exploitable flaw allows an attacker with network access via HTTP to perform unauthorized data modifications (update, insert, or delete) on some accessible data. With a CVSS score of 4.3 (Medium), its impact is limited to integrity, with no confidentiality or availability concerns. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0.0.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:business_intelligence:7.0.0.0.0:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.