What Is Oracle BI Publisher?
Oracle BI Publisher (formerly XML Publisher) is an enterprise reporting engine bundled with Oracle Fusion Middleware and widely used to generate formatted reports — invoices, statements, regulatory documents — from data held in ERP, HR, and other business systems. Because BI Publisher sits close to sensitive business data and is often deployed on internal application servers, unauthorized access to it can expose confidential organizational information.
Overview
CVE-2019-2616 is an unauthorized access vulnerability in Oracle BI Publisher, patched as part of Oracle's April 2019 Critical Patch Update. It allows a low-complexity, unauthenticated network attacker to obtain unauthorized read access to information handled by BI Publisher, with a CVSS score of 7.2 (Scope: Changed, reflecting that the vulnerable component can affect resources beyond its own security scope).
Technical Details
Oracle's advisories for this class of finding rarely disclose granular root-cause detail, describing it only as an "easily exploitable vulnerability [that] allows unauthenticated attacker with network access via HTTP to compromise" BI Publisher, with successful exploits able to result in unauthorized access to a subset of accessible data. Public reporting following the patch generally attributes it to an authentication/access-control bypass in the BI Publisher web interface, allowing certain requests or endpoints to be reached without valid credentials. The attack requires only network access to the affected HTTP interface and no user interaction.
Discovery
This vulnerability was addressed through Oracle's routine quarterly Critical Patch Update process rather than a named independent researcher disclosure documented here.
Exploitation Context
CISA's KEV addition confirms this vulnerability has been observed exploited in the wild, several years after the original patch — consistent with the broader pattern of unpatched, internet- or intranet-exposed Oracle Fusion Middleware components (a frequent target given how long enterprises often run business-critical middleware without applying CPUs). Attackers scanning for exposed BI Publisher instances can use this bypass to harvest reporting data as a reconnaissance or data-theft step in broader intrusions.
Remediation
- Apply Oracle's April 2019 Critical Patch Update (or any later CPU that supersedes it) to the affected BI Publisher installation.
- Restrict network access to BI Publisher and other Fusion Middleware components to trusted internal networks — avoid direct internet exposure.
- Establish a regular Oracle CPU cadence — Oracle Fusion Middleware components are frequently targeted specifically because organizations delay applying quarterly patches.
- Review BI Publisher access logs for anomalous unauthenticated requests that could indicate exploitation attempts.
- Audit for stale or unsupported Fusion Middleware versions that may no longer receive patches and should be upgraded or decommissioned.
Key Details
| Property | Value |
|---|---|
| CVE ID | CVE-2019-2616 |
| Vendor / Product | Oracle — BI Publisher (Formerly XML Publisher) |
| NVD Published | 2019-04-23 |
| NVD Last Modified | 2026-01-13 |
| CVSS 3.1 Score | 7.2 |
| CVSS 3.1 Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
| Severity | HIGH |
| CISA KEV Added | 2022-03-25 |
| CISA KEV Deadline | 2022-04-15 |
| Known Ransomware Use | No |
CVSS 3.1 Breakdown
Required Action
Timeline
| Date | Event |
|---|---|
| 2019-04-16 | Oracle Critical Patch Update (April 2019) addresses the vulnerability |
| 2019-04-23 | CVE-2019-2616 published |
| 2022-03-25 | Added to CISA Known Exploited Vulnerabilities catalog |
| 2022-04-15 | CISA BOD 22-01 remediation deadline |
References
| Resource | Type |
|---|---|
| NVD — CVE-2019-2616 | Vulnerability Database |
| CISA KEV Catalog Entry | US Government |