Impact
A flaw in the Pod Admin component of Oracle Business Intelligence Enterprise Edition permits unauthenticated HTTP requests, allowing an attacker to read all data accessible by the product and cause a partial denial of service. The vulnerability correlates with a high confidentiality impact and a moderate availability impact, as reflected by a CVSS 3.1 score of 8.2.
Affected Systems
Oracle Business Intelligence Enterprise Edition versions 8.2.0.0.0 and 26.01.0.0.0, which are part of Oracle Analytics, are affected. The flaw targets the Pod Admin service available over HTTP.
Risk and Exploitability
The flaw can be exploited over the network; an attacker who can reach the Pod Admin HTTP endpoint can send unauthorized requests. Successful exploitation results in unrestricted access to all data and may degrade availability. The CVSS score of 8.2 indicates a high severity, while the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, but the combination of high severity and remote access still warrants priority remediation.
OpenCVE Enrichment