Impact
Oracle Business Intelligence Enterprise Edition contains a remote, unauthenticated flaw in the BI Platform Security component that allows an attacker to send crafted HTTP requests. Successful exploitation can cause the application to hang or crash, resulting in a complete denial of service. The same flaw also permits the attacker to insert, update, delete, or read data exposed by the BI service, thereby compromising confidentiality and integrity. The weakness is rooted in improperly controlled access and missing authentication, reflected by CWE‑284 and CWE‑306.
Affected Systems
The vulnerability affects Oracle Business Intelligence Enterprise Edition versions 8.2.0.0.0 and 26.01.0.0.0, the builds listed as impacted by Oracle.
Risk and Exploitability
With a CVSS 3.1 base score of 8.6, the issue is high severity. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, yet the attack is considered easily exploitable and requires only network access via HTTP. An unauthenticated attacker can reach the vulnerable component from any network location that can reach the BI server, making the threat both remote and widely reachable.
OpenCVE Enrichment