CVE-2019-2616 — Oracle BI Publisher Unauthorized Access Vulnerability

CVE-2019-2616

Oracle BI Publisher — Unauthenticated Access Bypass in a Widely Deployed Reporting Engine

What Is Oracle BI Publisher?

Oracle BI Publisher (formerly XML Publisher) is an enterprise reporting engine bundled with Oracle Fusion Middleware and widely used to generate formatted reports — invoices, statements, regulatory documents — from data held in ERP, HR, and other business systems. Because BI Publisher sits close to sensitive business data and is often deployed on internal application servers, unauthorized access to it can expose confidential organizational information.

Overview

CVE-2019-2616 is an unauthorized access vulnerability in Oracle BI Publisher, patched as part of Oracle's April 2019 Critical Patch Update. It allows a low-complexity, unauthenticated network attacker to obtain unauthorized read access to information handled by BI Publisher, with a CVSS score of 7.2 (Scope: Changed, reflecting that the vulnerable component can affect resources beyond its own security scope).

Technical Details

Oracle's advisories for this class of finding rarely disclose granular root-cause detail, describing it only as an "easily exploitable vulnerability [that] allows unauthenticated attacker with network access via HTTP to compromise" BI Publisher, with successful exploits able to result in unauthorized access to a subset of accessible data. Public reporting following the patch generally attributes it to an authentication/access-control bypass in the BI Publisher web interface, allowing certain requests or endpoints to be reached without valid credentials. The attack requires only network access to the affected HTTP interface and no user interaction.

Discovery

This vulnerability was addressed through Oracle's routine quarterly Critical Patch Update process rather than a named independent researcher disclosure documented here.

Exploitation Context

CISA's KEV addition confirms this vulnerability has been observed exploited in the wild, several years after the original patch — consistent with the broader pattern of unpatched, internet- or intranet-exposed Oracle Fusion Middleware components (a frequent target given how long enterprises often run business-critical middleware without applying CPUs). Attackers scanning for exposed BI Publisher instances can use this bypass to harvest reporting data as a reconnaissance or data-theft step in broader intrusions.

Remediation

  1. Apply Oracle's April 2019 Critical Patch Update (or any later CPU that supersedes it) to the affected BI Publisher installation.
  2. Restrict network access to BI Publisher and other Fusion Middleware components to trusted internal networks — avoid direct internet exposure.
  3. Establish a regular Oracle CPU cadence — Oracle Fusion Middleware components are frequently targeted specifically because organizations delay applying quarterly patches.
  4. Review BI Publisher access logs for anomalous unauthenticated requests that could indicate exploitation attempts.
  5. Audit for stale or unsupported Fusion Middleware versions that may no longer receive patches and should be upgraded or decommissioned.

Key Details

PropertyValue
CVE ID CVE-2019-2616
Vendor / Product Oracle — BI Publisher (Formerly XML Publisher)
NVD Published2019-04-23
NVD Last Modified2026-01-13
CVSS 3.1 Score7.2
CVSS 3.1 VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
SeverityHIGH
CISA KEV Added2022-03-25
CISA KEV Deadline2022-04-15
Known Ransomware Use No

CVSS 3.1 Breakdown

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Required Action

CISA BOD 22-01 Deadline: 2022-04-15. Apply updates per vendor instructions.

Timeline

DateEvent
2019-04-16Oracle Critical Patch Update (April 2019) addresses the vulnerability
2019-04-23CVE-2019-2616 published
2022-03-25Added to CISA Known Exploited Vulnerabilities catalog
2022-04-15CISA BOD 22-01 remediation deadline

References

ResourceType
NVD — CVE-2019-2616 Vulnerability Database
CISA KEV Catalog Entry US Government