Impact
The vulnerability resides in the Platform Security component of Oracle Business Intelligence Enterprise Edition and is an instance of improper access control. An attacker who can reach the system over HTTP, even with a low‑privileged account, can exploit the flaw to compromise the BI platform. Successful exploitation leads to full takeover, impacting confidentiality, integrity and availability.
Affected Systems
Oracle Business Intelligence Enterprise Edition version 12.2.1.4.0 from Oracle Corporation is the only product listed as affected. No other product variants or versions are identified.
Risk and Exploitability
The CVSS base score of 8.8 reflects a high severity, with low attack complexity and low privileged access required. Exploitation is possible over HTTP and the official advisories note that a successful attack can result in full takeover. The EPSS score is reported to be less than 1%, indicating a very low current probability of exploitation, though this does not preclude future exploitation. The vulnerability is not listed in the CISA KEV catalog, but the combination of high impact and easy network access makes it a significant risk for any organization that has exposed Oracle BI to external traffic.
OpenCVE Enrichment