Impact
The flaw resides in the BI Platform Security component of Oracle Business Intelligence Enterprise Edition, allowing an unauthenticated attacker reachable over HTTP to bypass existing security controls. Successful exploitation grants the attacker unauthorized read access to critical data and, in many cases, full access to all data exposed by the platform, plus the ability to create, modify or delete data entries. The impact is high confidentiality loss and moderate integrity compromise, resulting in potential data exfiltration and tampering.
Affected Systems
Oracle Business Intelligence Enterprise Edition, part of Oracle Analytics, is affected in the supported versions 8.2.0.0.0 and 26.01.0.0.0. Any installation of this enterprise edition that exposes the BI platform over HTTP is susceptible, regardless of environment or network location, as the issue hinges solely on HTTP access to the platform.
Risk and Exploitability
The CVSS 3.1 base score of 8.2 classifies this issue as high severity, while an EPSS score of less than 1% indicates a low current probability of exploitation. The vulnerability is absent from the CISA KEV catalog. Exploitation requires only network connectivity to an HTTP endpoint and no user credentials or privileged access, making the attack vector simple and straightforward.
OpenCVE Enrichment