4
CVSSv2

CVE-2016-3473

Published: 25/10/2016 Updated: 03/09/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 7.7 | Impact Score: 4 | Exploitability Score: 3.1
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote authenticated users to affect confidentiality via unknown vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oracle business intelligence publisher 12.2.1.0.0

oracle business intelligence publisher 11.1.1.9.0

oracle business intelligence publisher 11.1.1.7.0

Exploits

# Exploit Title: Oracle BI Publisher (formerly XML Publisher) - XML External Entity Injection w/o authentication # Date: 20\10\2016 # Exploit Author: Jakub Palaczynski # CVE : CVE-2016-3473 # Vendor Homepage: wwworaclecom/ # Version: 111160, 111170, 111190, 122100 # Info: Previous versions may also be vulnerable # Google ...