Vulnerability record · CVE-2019-2616 · published 23 April 2019
CVE-2019-2616: Oracle BI Publisher unauthenticated data read and write flaw
Oracle · Business Intelligence Publisher
Oracle Fusion Middleware BI Publisher (formerly XML Publisher) contains a security flaw in the BI Publisher Security subcomponent affecting versions 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. An unauthenticated attacker with network access via HTTP can exploit it to read and modify some BI Publisher accessible data. The record does not describe the underlying root cause, so the exact mechanism is unknown.
Description
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). While the vulnerability is in BI Publisher (formerly XML Publisher), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of BI Publisher (formerly XML Publisher) accessible data as well as unauthorized read access to a subset of BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Automated analysis
critical priorityThe flaw is unauthenticated, network reachable, listed in CISA KEV as exploited in the wild, and carries a very high EPSS probability.
What it is
Oracle Fusion Middleware BI Publisher (formerly XML Publisher) contains a security flaw in the BI Publisher Security subcomponent affecting versions 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. An unauthenticated attacker with network access via HTTP can exploit it to read and modify some BI Publisher accessible data. The record does not describe the underlying root cause, so the exact mechanism is unknown.
Impact
An attacker gains unauthorized read access to a subset of BI Publisher data and can update, insert or delete some of that data. The CVSS scope change indicates compromise can significantly impact additional products beyond BI Publisher itself.
Attack surface
Reachable over the network via HTTP with no authentication and no user interaction required, per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The description confirms an unauthenticated attacker with network access can exploit it.
Exploitation
CVE-2019-2616 is listed in CISA KEV with a due date of 2022-04-15, indicating known exploitation in the wild, and EPSS gives a 30-day probability of 0.92183 (99.8th percentile). No ransomware campaign use is documented.
What to do
- Apply the Oracle April 2019 Critical Patch Update for BI Publisher versions 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0.
- If patching cannot be done immediately, restrict network access to BI Publisher HTTP endpoints to trusted hosts only.
- Place BI Publisher behind a reverse proxy or WAF and block unauthenticated access to administrative and security endpoints.
- Review and rotate credentials and secrets that may be reachable through BI Publisher data stores.
- Monitor Oracle advisories for any follow-up fixes affecting the same component.
Detection
- Review BI Publisher HTTP access logs for unauthenticated requests to security or administrative paths, especially from unexpected source IPs.
- Alert on anomalous read or write activity against BI Publisher data stores outside normal application behavior.
- Hunt for exploitation attempts using the KEV-listed vulnerability name and correlate with outbound or lateral traffic from BI Publisher hosts.
- Baseline normal BI Publisher request patterns and flag deviations in volume, timing or endpoint targeting.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-2616 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Oracle BI Publisher Unauthorized Access Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html | PatchVendor Advisory |
| http://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-2616 | US Government Resource |
Track CVE-2019-2616 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-2616), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.