HomeVulnerabilitiesCVE-2019-2767
Disclosed

CVE-2019-2767

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The supported version that is affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). While the vulnerability is in BI Publisher (formerly XML Publisher), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of BI Publisher (formerly XML Publisher) accessible data as well as unauthorized read access to a subset of BI Publisher (formerly XML Publisher) accessible data.

Share this vulnerability:

Exploitation Probability (EPSS)

Medium Priority
49.89%

The Exploit Prediction Scoring System (EPSS) uses machine learning to estimate the probability that a vulnerability will be exploited in the wild within the next 30 days.

0% (Theoretical)100% (Certainty)

7-Day Exploitation Trend

Vulnerability Timeline

4 events
Jul 23, 2019
Vulnerability Disclosed
Published to component-level vulnerability database.
Oct 15, 2020
Last Updated
Record updated with new analysis or tags.
Jul 2, 2025
EPSS Score Decreased
Daily EPSS score decreased by 0.140 on 2023-12-30
Jul 5, 2025
EPSS Score Increased
Daily EPSS score increased by 0.140 on 2023-12-30

Threat Actor Attribution

PREMIUM INTEL
Associated Groups:Lazarus Group, APT28
Ransomware Campaigns:LockBit 3.0, BlackCat
IoCs (Indicators):14 IPs, 3 Hashes

Remediation & Mitigation

SOLUTION

Official patches and mitigation steps are available for this vulnerability.

# Update Command
apt-get update && apt-get upgrade -y specific-package
# Verify installation
dpkg -l | grep package-name

Affected Products

1 Total
oracle/bi_publisher11.1.1.9.0

Am I Vulnerable?

Check your domain or package.json for CVE-2019-2767 exposure.

Share This Page

Help others discover this vulnerability information

Vulnerability Details

CVSS Base Score
6.4/ 10
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:N
Published Date
Jul 23, 2019
Last Modified
Oct 15, 2020
Need API Access?

Integrate this data into your SOAR platform.

View Plans →
Need Manual Validation?

Automated scanners flag false positives. Get a manual pentest validation for this CVE.