Impact
The reported weakness in Oracle Operations Intelligence's Daily Business Intelligence component allows an attacker with low privileges to gain control of the system. An attacker with network connectivity to HTTP endpoints can exploit the vulnerability and achieve a takeover of Oracle Operations Intelligence, impacting confidentiality, integrity, and availability.
Affected Systems
Affected by Oracle Corporation: Oracle Operations Intelligence. The versions impacted are 12.2.3 through 12.2.15. Any installation of these versions deployed behind an HTTP interface is vulnerable.
Risk and Exploitability
The vulnerability is rated CVSS 7.5 with high impact on confidentiality, integrity, and availability, but has a high attack complexity and requires only low privileges. The EPSS score is 0.00345 (less than 1%), and the vulnerability is not listed in CISA's KEV catalog. It can be exploited from any network point that can reach the HTTP interface, allowing a remote compromise with minimal effort and potentially full control of the Oracle Operations Intelligence environment.
OpenCVE Enrichment