Download
Security Advisory; NCSC-2026-0259 [1.0.0]
- Security Advisory
- NCSC-2026-0259 [1.0.0]
- Publicatie
- 22-07-2026 17:22 (Europe/Amsterdam)
- Prioriteit
- Normaal
- Betreft
- Kwetsbaarheden verholpen in Oracle Analytics
Kenmerken
- Improper Encoding or Escaping of Output
- Improper Restriction of Operations within the Bounds of a Memory Buffer
- Incorrect Calculation of Buffer Size
- Improper Handling of Inconsistent Special Elements
Omschrijving
Oracle heeft meerdere kwetsbaarheden verholpen in Oracle BI Publisher (versies 8.2.0.0.0, 12.2.1.4.0 en 26.01.0.0.0) en Oracle Business Intelligence Enterprise Edition (versies 8.2.0.0.0 en 26.01.0.0.0).
De kwetsbaarheden in Oracle BI Publisher en Oracle Business Intelligence Enterprise Edition stellen ongeauthenticeerde aanvallers in staat via HTTP-verzoeken volledige systeemcompromittering te bereiken, authenticatie te omzeilen, willekeurige code uit te voeren, denial of service aanvallen uit te voeren en ongeautoriseerde lees-, update-, insert- of delete-operaties op onderliggende data uit te voeren. Daarnaast kunnen laaggeprivilegieerde aanvallers via de Web Service API authenticatiecontroles omzeilen, wat leidt tot ongeautoriseerde toegang tot gevoelige data, wijziging of verwijdering van kritieke informatie en gedeeltelijke denial of service condities.
Oplossingen
Apache heeft een fix uitgebracht in Apache Log4j versie 2.25.4. Oracle heeft updates uitgebracht voor Oracle BI Publisher en Oracle Business Intelligence Enterprise Edition om de beschreven kwetsbaarheden te verhelpen. Daarnaast is de buffer overflow in de cryptography package opgelost in versie 46.0.7. Zie bijgevoegde referenties voor meer informatie.
Referenties
CVE's
- CVE-2026-34480 - CVSS (v4) 6.9
- CVE-2026-39892 - CVSS (v4) 6.9
- CVE-2026-60173 - CVSS (v3) 9.8
- CVE-2026-60671 - CVSS (v3) 8.6
- CVE-2026-60673 - CVSS (v3) 6.5
- CVE-2026-60674 - CVSS (v3) 8.2
- CVE-2026-60719 - CVSS (v3) 9.9
Producten
Oracle
Disclaimer
The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this page to enhance access to its information and security advisories. The use of this security advisory is subject to the following terms and conditions: NCSC-NL makes every reasonable effort to ensure that the content of this page is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or continuous keeping up-to-date. The information contained in this security advisory is intended solely for the purpose of providing general information to professional users. No rights can be derived from the information provided therein. NCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of this security advisory. This includes damage resulting from the inaccuracy of incompleteness of the information contained in the advisory. This security advisory is subject to Dutch law. All disputes related to or arising from the use of this advisory will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings.