Impact
Oracle BI Publisher is vulnerable through its XML Services component, allowing an attacker with limited local privileges who can reach the HTTP interface to gain unauthorized access to any data the publisher holds. The flaw can be exploited easily, exposing sensitive reports, configuration files, or other stored information, and in the worst case can provide complete control over all data available through Oracle BI Publisher.
Affected Systems
Version 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0 of Oracle BI Publisher are affected. These versions are used in Oracle Analytics deployments that expose reported data through web services.
Risk and Exploitability
The CVSS v3.1 score of 6.5 indicates moderate severity, with a high confidentiality impact and no impact to integrity or availability. The EPSS score of less than 1% suggests exploitation is unlikely in the near term and the vulnerability is not listed in the CISA KEV catalogue. The likely attack vector is remote, via HTTP to the XML Services endpoint, and the exploit requires only low privileged access.
OpenCVE Enrichment