Impact
Oracle BI Publisher’s platform security module contains a defect that lets an attacker with low privileges and network connectivity over HTTP create, delete or modify data, and potentially cause a partial denial of service. The flaw exposes confidentiality, integrity, and availability, allowing unauthorized access to critical data or all data published through BI Publisher.
Affected Systems
The vulnerability affects Oracle BI Publisher, a component of Oracle Analytics. Versions 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0 are known to be vulnerable and have been documented by Oracle’s security advisory.
Risk and Exploitability
The issue carries a CVSS 3.1 score of 8.3, indicating high severity. The EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV catalog, implying no publicly known exploits at the time of reporting. The likely attack vector is over the network via HTTP, requiring only low privileges to exploit, making this a readily exploitable threat for attackers with network access to the application.
OpenCVE Enrichment