Lucene search

K
nessusThis script is Copyright (C) 2021-2022 and is owned by Tenable, Inc. or an Affiliate thereof.ORACLE_BI_PUBLISHER_JAN_2021_CPU.NASL
HistoryMar 10, 2021 - 12:00 a.m.

Oracle Business Intelligence Publisher Multiple Vulnerabilities (Jan 2021 CPU)

2021-03-1000:00:00
This script is Copyright (C) 2021-2022 and is owned by Tenable, Inc. or an Affiliate thereof.
www.tenable.com
25
oracle business intelligence publisher
oracle analytics server
vulnerabilities
fusion middleware
critical patch update
unauthorized access
remote exploit
http
data security
denial of service
nessus

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

7.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N

EPSS

0.001

Percentile

36.0%

The version of Oracle Business Intelligence Publisher or Oracle Analytics Server 5.5 running on the remote host is 11.1.1.9.x prior to 11.1.1.9.210119, 12.2.1.3.x prior to 12.2.1.3.201216, 12.2.1.4.x prior to 12.2.1.4.201216, or 12.2.5.5.x (OAS 5.5) prior to 12.2.5.5.201216. It is, therefore, affected by multiple vulnerabilities as noted in the January 2021 Critical Patch Update advisory:

  • An unspecified vulnerability exists in the BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). An unauthenticated, remote attacker can exploit this, via HTTP, which can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. (CVE-2021-2013)

  • An unspecified vulnerability exists in the BI Publisher product of Oracle Fusion Middleware (component: Administration). An unauthenticated, remote attacker can exploit this, via HTTP, which can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. (CVE-2021-2049)

  • An unspecified vulnerability exists in the BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). An unauthenticated, remote attacker can exploit this, via HTTP, which can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. (CVE-2021-2050, CVE-2021-2051)

  • An unspecified vulnerability exists in the BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). An unauthenticated, remote attacker can exploit this, via HTTP, which can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. (CVE-2021-2051)

  • An unspecified vulnerability exists in the BI Publisher product of Oracle Fusion Middleware (component: Web Server). An unauthenticated, remote attacker can exploit this, via HTTP, which can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data. (CVE-2021-2062)

Note that Nessus has not tested for these issues but has instead relied only on the application’s self-reported version number.

#%NASL_MIN_LEVEL 70300
##
# (C) Tenable Network Security, Inc.
##

include('deprecated_nasl_level.inc');
include('compat.inc');

if (description)
{
  script_id(147639);
  script_version("1.5");
  script_set_attribute(attribute:"plugin_modification_date", value:"2022/12/05");

  script_cve_id(
    "CVE-2021-2013",
    "CVE-2021-2049",
    "CVE-2021-2050",
    "CVE-2021-2051",
    "CVE-2021-2062"
  );
  script_xref(name:"CEA-ID", value:"CEA-2021-0004");

  script_name(english:"Oracle Business Intelligence Publisher Multiple Vulnerabilities (Jan 2021 CPU)");

  script_set_attribute(attribute:"synopsis", value:
"The remote host is affected by multiple vulnerabilities.");
  script_set_attribute(attribute:"description", value:
"The version of Oracle Business Intelligence Publisher or Oracle Analytics Server 5.5 running on the remote host is
11.1.1.9.x prior to 11.1.1.9.210119, 12.2.1.3.x prior to 12.2.1.3.201216, 12.2.1.4.x prior to 12.2.1.4.201216, or
12.2.5.5.x (OAS 5.5) prior to 12.2.5.5.201216. It is, therefore, affected by multiple vulnerabilities as noted in
the January 2021 Critical Patch Update advisory:

  - An unspecified vulnerability exists in the BI Publisher product of Oracle Fusion Middleware (component: BI 
    Publisher Security). An unauthenticated, remote attacker can exploit this, via HTTP, which can result in 
    unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well 
    as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized 
    ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. (CVE-2021-2013)

  - An unspecified vulnerability exists in the BI Publisher product of Oracle Fusion Middleware (component: 
    Administration). An unauthenticated, remote attacker can exploit this, via HTTP, which can result in 
    unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as 
    well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and 
    unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. (CVE-2021-2049)
  
  - An unspecified vulnerability exists in the BI Publisher product of Oracle Fusion Middleware (component: 
    E-Business Suite - XDO). An unauthenticated, remote attacker can exploit this, via HTTP, which can result in 
    unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as 
    unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized 
    ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. (CVE-2021-2050, CVE-2021-2051)
  
  - An unspecified vulnerability exists in the BI Publisher product of Oracle Fusion Middleware (component: BI
    Publisher Security). An unauthenticated, remote attacker can exploit this, via HTTP, which can result in 
    unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as 
    unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized 
    ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. (CVE-2021-2051)

  - An unspecified vulnerability exists in the BI Publisher product of Oracle Fusion Middleware (component: 
    Web Server). An unauthenticated, remote attacker can exploit this, via HTTP, which can result in unauthorized 
    access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized 
    update, insert or delete access to some of Oracle BI Publisher accessible data. (CVE-2021-2062)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version
number.");
  script_set_attribute(attribute:"see_also", value:"https://www.oracle.com/security-alerts/cpujan2021.html");
  script_set_attribute(attribute:"solution", value:
"Apply the appropriate patch according to the January 2021 Oracle Critical Patch Update advisory.");
  script_set_attribute(attribute:"agent", value:"all");
  script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P");
  script_set_cvss_temporal_vector("CVSS2#E:U/RL:OF/RC:C");
  script_set_cvss3_base_vector("CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N");
  script_set_cvss3_temporal_vector("CVSS:3.0/E:U/RL:O/RC:C");
  script_set_attribute(attribute:"cvss_score_source", value:"CVE-2021-2051");
  script_set_attribute(attribute:"cvss3_score_source", value:"CVE-2021-2062");

  script_set_attribute(attribute:"exploitability_ease", value:"No known exploits are available");

  script_set_attribute(attribute:"vuln_publication_date", value:"2021/01/20");
  script_set_attribute(attribute:"patch_publication_date", value:"2021/01/20");
  script_set_attribute(attribute:"plugin_publication_date", value:"2021/03/10");

  script_set_attribute(attribute:"plugin_type", value:"local");
  script_set_attribute(attribute:"cpe", value:"cpe:/a:oracle:fusion_middleware");
  script_set_attribute(attribute:"cpe", value:"cpe:/a:oracle:business_intelligence_publisher");
  script_set_attribute(attribute:"thorough_tests", value:"true");
  script_end_attributes();

  script_category(ACT_GATHER_INFO);
  script_family(english:"Misc.");

  script_copyright(english:"This script is Copyright (C) 2021-2022 and is owned by Tenable, Inc. or an Affiliate thereof.");

  script_dependencies("oracle_bi_publisher_installed.nbin");
  script_require_keys("installed_sw/Oracle Business Intelligence Publisher");

  exit(0);
}

include('vcf.inc');
include('vcf_extras.inc');

app_info = vcf::get_app_info(app:'Oracle Business Intelligence Publisher');

constraints = [
  {'min_version': '11.1.1.9', 'fixed_version': '11.1.1.9.210119', 'patch': '32293873', 'bundle': '32310890'},
  {'min_version': '12.2.1.3', 'fixed_version': '12.2.1.3.201216', 'patch': '32294042', 'bundle': '32294042'},
  {'min_version': '12.2.1.4', 'fixed_version': '12.2.1.4.201216', 'patch': '32294048', 'bundle': '32294048'},
  # Oracle Analytics Server 5.5
  {'min_version': '12.2.5.5', 'fixed_version': '12.2.5.5.201216', 'patch': '32294034', 'bundle': '32294034'}
];

vcf::oracle_bi_publisher::check_version_and_report(app_info: app_info, constraints:constraints, severity:SECURITY_WARNING);

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

7.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N

EPSS

0.001

Percentile

36.0%

Related for ORACLE_BI_PUBLISHER_JAN_2021_CPU.NASL