Impact
A low‑privileged attacker can exploit the Web Service API of Oracle BI Publisher through an HTTP connection to change, delete, or create data, gain full read access to all data, and cause a partial denial of service. The flaw is rooted in multiple weak points: improper input validation (CWE‑20), missing or insecure authorization checks (CWE‑269, CWE‑284, CWE‑285), denial‑of‑service conditions (CWE‑400) and data leakage through reduced access controls (CWE‑639). The CVSS 3.1 vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L indicates that the attacker needs only network connectivity, no user interaction, and benefits from a compromised confidentiality, integrity, and the availability of the system.
Affected Systems
The affected product is Oracle BI Publisher (Oracle Analytics) provided by Oracle Corporation. Vulnerable versions are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0.
Risk and Exploitability
With a CVSS base score of 9.9 the vulnerability is classed as critical, yet the EPSS score of less than 1% suggests a very low likelihood that it is currently being exploited. The vulnerability is not listed in CISA’s KEV catalog, but because it has a scope change it may impact additional products if the attacker gains further control. The attack path is a simple network‑based request to a Web Service API; no privileged credentials or user interaction are required, making it quickly exploitable if the system is exposed.
OpenCVE Enrichment