CVE-2019-2588
72Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 37%
from disclosure to weapon0 days
Published on NVDApr 23
1st PoCApr 19
VulnCheck+1735d
exploitation probability
37%top 2% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).
Affected products
Oracle Corporation · BI Publisher (formerly XML Publisher)public PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/46728⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.