A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2025-50060

CVE-2025-50060: Oracle BI Publisher Auth Bypass Flaw

CVE-2025-50060 is an authentication bypass vulnerability in Oracle BI Publisher that allows low-privileged attackers to gain unauthorized access to critical data. This article covers technical details, affected versions, and mitigation.

Published: May 26, 2026

CVE-2025-50060 Overview

CVE-2025-50060 is an improper access control vulnerability [CWE-284] affecting the Web Server component of Oracle BI Publisher, part of Oracle Analytics. The flaw allows a low-privileged attacker with network access via HTTP to compromise the application. Successful exploitation can lead to unauthorized creation, deletion, or modification of critical data and full read access to all data accessible through Oracle BI Publisher. Oracle addressed the issue in the July 2025 Critical Patch Update.

Critical Impact

Authenticated attackers with low privileges can compromise the confidentiality and integrity of all data accessible through Oracle BI Publisher over HTTP.

Affected Products

  • Oracle BI Publisher 7.6.0.0.0
  • Oracle BI Publisher 8.2.0.0.0
  • Oracle BI Publisher 12.2.1.4.0

Discovery Timeline

  • 2025-07-15 - CVE-2025-50060 published to NVD
  • 2025-07-15 - Oracle releases security patch in July 2025 Critical Patch Update
  • 2025-07-24 - Last updated in NVD database

Technical Details for CVE-2025-50060

Vulnerability Analysis

The vulnerability resides in the Web Server component of Oracle BI Publisher. It is classified under Improper Access Control [CWE-284], meaning the application fails to enforce proper authorization checks on certain HTTP-accessible functionality. An attacker who already holds a low-privileged account can reach restricted resources or operations that should require higher privilege levels.

Oracle's advisory indicates the impacted operations affect both confidentiality and integrity. Once exploited, an attacker can read, create, delete, or modify any data that the BI Publisher instance can access. Because BI Publisher commonly connects to enterprise data warehouses and operational reporting databases, the blast radius extends well beyond the application itself.

The Exploit Prediction Scoring System (EPSS) currently estimates a modest probability of exploitation activity, but the low attack complexity and network reachability make this issue attractive for opportunistic credential-based attacks.

Root Cause

The root cause is improper enforcement of access control on HTTP-exposed BI Publisher functionality. Authorization decisions appear to trust client-supplied context rather than validating the authenticated user's effective permissions against the requested resource or operation.

Attack Vector

Exploitation occurs over the network using standard HTTP requests against an exposed Oracle BI Publisher Web Server endpoint. The attacker must possess a low-privileged account on the target instance. No user interaction is required, and the scope remains unchanged. Verified public proof-of-concept code was not available at the time of writing. Refer to the Oracle Security Alert July 2025 for vendor technical details.

Detection Methods for CVE-2025-50060

Indicators of Compromise

  • Unexpected HTTP requests from low-privileged BI Publisher accounts targeting administrative or data-export endpoints.
  • Sudden spikes in report generation, data source queries, or template modifications outside normal business hours.
  • New or modified BI Publisher data models, reports, or scheduled jobs created by accounts that historically do not perform such actions.

Detection Strategies

  • Inspect BI Publisher access logs for authenticated sessions accessing resources outside the user's typical role scope.
  • Correlate authentication events with privileged operations performed by accounts that should not have those privileges.
  • Compare the running BI Publisher build against the July 2025 Critical Patch Update version baseline.

Monitoring Recommendations

  • Forward BI Publisher and WebLogic access logs to a centralized SIEM for behavioral analysis of report and data-source activity.
  • Alert on creation, deletion, or modification of BI Publisher catalog objects by non-administrative accounts.
  • Monitor outbound database connections originating from the BI Publisher service for unusual queries or volumes.

How to Mitigate CVE-2025-50060

Immediate Actions Required

  • Apply the July 2025 Critical Patch Update from Oracle to all affected BI Publisher deployments.
  • Inventory all instances of Oracle BI Publisher versions 7.6.0.0.0, 8.2.0.0.0, and 12.2.1.4.0 and prioritize internet-exposed systems.
  • Review and rotate credentials for low-privileged BI Publisher accounts, especially shared or service accounts.

Patch Information

Oracle published the fix in the Oracle Security Alert July 2025 Critical Patch Update. Administrators should deploy the corresponding patch for their specific BI Publisher version and validate the build number post-deployment.

Workarounds

  • Restrict network access to BI Publisher Web Server endpoints to trusted management subnets using firewall or reverse proxy rules.
  • Place BI Publisher behind a Web Application Firewall and enforce strict authentication on all HTTP routes until patching is complete.
  • Audit and minimize BI Publisher account permissions, removing unnecessary low-privileged users that could be leveraged for exploitation.
bash
# Example: restrict BI Publisher HTTP access to a management CIDR using iptables
iptables -A INPUT -p tcp --dport 9502 -s 10.10.20.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 9502 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeAuth Bypass

  • Vendor/TechOracle Bi Publisher

  • SeverityHIGH

  • CVSS Score8.1

  • EPSS Probability0.40%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityNone
  • CWE References
  • CWE-284
  • Vendor Resources
  • Oracle Security Alert July 2025
  • Related CVEs
  • CVE-2025-30724: Oracle BI Publisher Information Disclosure

  • CVE-2024-21082: Oracle BI Publisher RCE Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English