📦 Business Intelligence

by Oracle

🔍 What is Business Intelligence?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-23305

CRITICAL CVSS 9.8 Jan 18, 2022

CVE-2022-23305 is an SQL injection vulnerability in Log4j 1.2.x's JDBCAppender that allows attackers to execute arbitrary SQL queries by injecting malicious strings into application inputs that get lo...

CVE-2021-2456

CRITICAL CVSS 9.8 Jul 21, 2021

This critical vulnerability in Oracle Business Intelligence Enterprise Edition allows unauthenticated attackers with network access via HTTP to completely compromise the system. It affects version 12....

CVE-2020-17530

CRITICAL CVSS 9.8 Dec 11, 2020

This vulnerability in Apache Struts allows attackers to perform remote code execution by forcing OGNL evaluation on raw user input in tag attributes. It affects all Apache Struts 2 installations from ...

CVE-2026-21976

HIGH CVSS 7.1 Jan 20, 2026

This vulnerability in Oracle Business Intelligence Enterprise Edition allows authenticated attackers with local access to the infrastructure to manipulate or access critical data. It affects Oracle An...

CVE-2025-53049

HIGH CVSS 8.4 Oct 21, 2025

This vulnerability in Oracle Business Intelligence Enterprise Edition allows high-privileged attackers with network access to compromise the system via HTTP, requiring human interaction from another p...

CVE-2021-4104

HIGH CVSS 7.5 Dec 14, 2021

CVE-2021-4104 is a deserialization vulnerability in Log4j 1.2's JMSAppender that allows remote code execution when attackers can modify Log4j configuration files. This affects systems running Log4j 1....

CVE-2021-30468

HIGH CVSS 7.5 Jun 16, 2021

A denial-of-service vulnerability in Apache CXF's JsonMapObjectReaderWriter allows attackers to send specially crafted JSON payloads to web services, causing infinite loops that consume 100% CPU on af...

CVE-2025-30759

MEDIUM CVSS 6.1 Jul 15, 2025

This vulnerability in Oracle Business Intelligence Enterprise Edition allows unauthenticated attackers with network access via HTTP to compromise the system. It requires human interaction from someone...

CVE-2024-21139

MEDIUM CVSS 5.4 Jul 16, 2024

This vulnerability in Oracle Business Intelligence Enterprise Edition allows authenticated attackers with low privileges to manipulate or view sensitive data through the Analytics Web Answers componen...