CVE-2024-21082 is a critical vulnerability in Oracle BI Publisher's XML Services, affecting versions 7.0.0.0.0 and 12.2.1.4.0. This easily exploitable flaw allows an unauthenticated attacker with network access via HTTP to fully compromise the Oracle BI Publisher system, leading to complete loss of confidentiality, integrity, and availability. With a CVSS 3.1 Base Score of 9.8, it poses a severe risk. Despite its high severity, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it has not been observed in active exploitation or gained significant community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0.0.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:bi_publisher:7.0.0.0.0:*:*:*:*:*:*:* | ||
12.2.1.4.0CPE matchmatch criteria | cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.