LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-2616: Oracle BI Publisher Unauthorized Access Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-2616 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for…

CVE-2019-2616 is an unauthorized access vulnerability in Oracle BI Publisher (formerly XML Publisher). Public reporting describes it as allowing various unauthorized actions, with open-source sources attributing it to authentication bypass. For organizations that rely on this reporting component, successful abuse can let an attacker reach functions or data they should not see, so teams should treat it as a priority to inventory and remediate according to the vendor advisory.

CISA directs defenders to apply updates per vendor instructions. Specifics such as exact affected builds, attack preconditions, and scoring are not restated here; confirm them directly against Oracle’s advisory before acting.

How it works

The underlying weakness is not assigned a CWE in the provided record. The CISA summary characterizes the issue as unspecified but enabling various unauthorized actions; open-source reporting links it to authentication bypass. In practical terms, that class of flaw means an attacker who can reach the BI Publisher interface or related endpoints may be able to skip or weaken normal login checks and then perform actions the product would otherwise restrict.

Abuse typically involves sending crafted requests to the exposed service so that the application accepts the caller as authorized when it should not. Without authenticated identity enforcement, the attacker may read, generate, or manipulate reports and related resources depending on how the product is deployed. Exact request formats, parameters, or exploit sequences are not provided in the facts and must not be assumed; treat any public proof-of-concept material with caution and validate behavior only in controlled lab conditions against the vendor’s description.

Am I affected? How to find it in your systems

Oracle BI Publisher is commonly deployed as part of Oracle Business Intelligence or as a standalone reporting engine used to generate and deliver formatted documents. It often runs on application servers inside enterprise networks or, less commonly, on internet-facing portals that expose report generation to partners or customers.

Inventory steps:

Telemetry that may indicate probing or exploitation includes repeated unauthenticated or anomalous requests to BI Publisher endpoints, sudden spikes in report-generation activity from unexpected source addresses, and authentication or authorization failures followed by successful privileged actions. Correlate web and application logs with identity-provider logs. Absence of clear signatures does not prove safety; the vulnerability description is high-level, so prioritize version-based detection.

How to remediate

Patch first. Apply the updates Oracle released for this CVE exactly as described in the vendor advisory and in line with CISA’s required action: “Apply updates per vendor instructions.” Use your standard Oracle patching process (OPatch or the appropriate release update mechanism), test in a non-production environment, then roll out to production with change control.

After patching:

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

These measures lower risk but do not replace the official patch. Schedule the update as soon as operationally feasible.

If your data may have been exposed

Actively exploited vulnerabilities can lead to unauthorized access and data exposure. If you have evidence of exploitation or cannot rule it out, follow your incident-response process: isolate affected systems, preserve logs, assess what reports or data stores were reachable, and notify stakeholders according to policy. You can also run a free exposure scan of your email addresses against known breach data to see whether credentials or identities associated with your organization have appeared in prior incidents, then force password resets and enable MFA where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedOracle · BI Publisher (Formerly XML Publisher)
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities