Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspusep2026.html |
|
Mon, 21 Sep 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated SOAP-based DoS and Data Manipulation in Oracle BI Publisher |
Mon, 21 Sep 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated SOAP-based Denial of Service and Data Access in Oracle BI Publisher | |
| Weaknesses | CWE-285 |
Mon, 21 Sep 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
ssvc
|
Sun, 20 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated SOAP-based Denial of Service and Data Access in Oracle BI Publisher | |
| Weaknesses | CWE-285 |
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated SOAP-based DoS and Data Modification in Oracle BI Publisher | |
| Weaknesses | CWE-200 CWE-284 CWE-400 |
Wed, 16 Sep 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated SOAP-based DoS and Data Modification in Oracle BI Publisher | |
| Weaknesses | CWE-200 CWE-284 CWE-400 |
Tue, 15 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle BI Publisher as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized read access to a subset of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H). | |
| First Time appeared |
Oracle
Oracle bi Publisher |
|
| CPEs | cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Oracle
Oracle bi Publisher |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-09-21T00:03:17.073Z
Reserved: 2026-08-31T15:40:57.350Z
Link: CVE-2026-83284
Updated: 2026-09-20T23:54:58.949Z
Status : Deferred
Published: 2026-09-15T20:18:41.033
Modified: 2026-09-21T01:16:29.390
Link: CVE-2026-83284
No data.
OpenCVE Enrichment
Updated: 2026-09-21T04:00:13Z