Automating HTML Sanitization in OBIEE: Securing BI Platforms Without Compromising Usability

dc.contributor.authorPreeta Pillai
dc.date.accessioned2025-09-22T06:10:42Z
dc.date.issued2023-10-11
dc.description.abstractAs Business Intelligence (BI) platforms remain integral to enterprise operations, ensuring their security is a top priority. Platforms like Oracle Business Intelligence Enterprise Edition (OBIEE) are widely used for reporting and analysis but can carry risks from embedded HTML content. This paper presents a scalable and automated approach to mitigate Cross-Site Scripting (XSS) vulnerabilities within OBIEE reports and dashboards. We outline a detailed methodology involving catalog extraction, HTML tag parsing, sanitization using html5lib and bleach, and secure redeployment. Key findings indicate a substantial reduction in remediation time and XSS risk. The study also contributes to practice by offering a replicable DevSecOps integration pipeline. Its theoretical value lies in demonstrating a practical framework for balancing security with usability in enterprise BI systems. Real-world scenarios, technical architecture examples, and implementation guidance are provided.
dc.identifier.citationVol. 4 No. 4 (2023)
dc.identifier.issn2958-7425
dc.identifier.otherhttps://doi.org/10.47941/ijce.2920
dc.identifier.urihttps://repository.carijournals.org/handle/20.500.14801/127
dc.language.isoen
dc.publisherCARI Journals
dc.subjectOBIEE
dc.subjectHTMLSanitization
dc.subjectXSS
dc.subjectBISecurity
dc.subjectDashboardAutomation
dc.subjectMetadataProtection
dc.subjectBleach
dc.subjectHTML5lib
dc.titleAutomating HTML Sanitization in OBIEE: Securing BI Platforms Without Compromising Usability
dc.typeArticle

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
2920-Article Text-7051-8091-10-20250714.pdf
Size:
603.93 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
2.15 KB
Format:
Item-specific license agreed to upon submission
Description: