Impact
A vulnerability in Oracle BI Publisher allows an unauthenticated attacker to remotely take over the application. The weakness, stemming from inadequate access control (CWE‑284), enables execution of arbitrary code through standard HTTP channels, leading to full compromise of confidentiality, integrity, and availability for the affected instance.
Affected Systems
Oracle BI Publisher versions 8.2.0.0.0 and 12.2.1.4.0 are impacted. These versions are part of Oracle Analytics and are widely deployed in enterprise environments.
Risk and Exploitability
The CVSS 3.1 score of 9.8 indicates critical severity. Although the EPSS score is below 1%, the vulnerability is exploitable with network access and no credentials, and is not currently listed in CISA KEV. Attackers could leverage the HTTP interface to trigger the exploit, potentially gaining full control of the BI Publisher server.
OpenCVE Enrichment