Oracle Business Intelligence Publisher (October 2012 CPU)

medium Nessus Plugin ID 73122

Synopsis

The remote Oracle Business Intelligence Publisher install is missing the Oracle 2012 Critical Patch Update.

Description

According to the self-reported version of the Remote Oracle Business Intelligence Publisher install, it is missing the October 2012 Critical Patch Update. It is, therefore, affected by multiple reflected cross-site scripting vulnerabilities and an XML eXternal Entity (XXE) injection vulnerability that could allow an authenticate user to gain access to arbitrary files.

Solution

Apply the appropriate Oracle Fusion Middleware October 2012 Critical Patch Update.

See Also

http://www.nessus.org/u?ec0452db

http://www.nessus.org/u?87547c81

Plugin Details

Severity: Medium

ID: 73122

File Name: oracle_bi_publisher_oct_2012_cpu.nasl

Version: 1.10

Type: remote

Family: CGI abuses

Published: 3/20/2014

Updated: 6/5/2024

Configuration: Enable thorough checks

Supported Sensors: Nessus

Enable CGI Scanning: true

Risk Information

VPR

Risk Factor: Low

Score: 2.5

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: cpe:/a:oracle:fusion_middleware

Required KB Items: installed_sw/Oracle BI Publisher

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Ease: No exploit is required

Patch Publication Date: 10/16/2012

Vulnerability Publication Date: 10/16/2012

Reference Information

CVE: CVE-2012-3193, CVE-2012-3194

BID: 55958, 56010

CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990