Description
XMLPService service of Oracle Business Intelligence has the authentication bypass vulnerability. Therefore, an attacker can interact with the server as an administrator and install additional plugins, which may lead to takeover of the server.
Remediation
Upgrade to the latest version of Oracle Business Intelligence. This issue was fixed in Oracle Critical Patch Update - July 2019
References
Related Vulnerabilities
phpMyAdmin Improper Input Validation Vulnerability (CVE-2013-5029)
MediaWiki Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2022-34750)
Oracle JRE CVE-2013-2447 Vulnerability (CVE-2013-2447)
Werkzeug WSGI URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-28724)