Impact
The vulnerability resides in the BI Search component of Oracle Business Intelligence Enterprise Edition and can be triggered by a low‑privileged attacker who has network access through HTTP. When exploited, the flaw permits the attacker to gain unauthorized access to critical data or even complete access to all data available in the BI Enterprise Edition environment. The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N) indicates that confidentiality is impacted while integrity and availability remain unaffected, reflecting the nature of an access‑control weakness that can expose sensitive information.
Affected Systems
Oracle Business Intelligence Enterprise Edition versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 are affected. These applications provide advanced analytics and reporting, and the impact may extend to other Oracle products through a scope change.
Risk and Exploitability
With a CVSS base score of 7.7 the vulnerability is considered high severity. The EPSS score is less than 1%, indicating a very low but nonzero chance of exploitation in the wild. The lack of a KEV listing does not reduce the risk, as the flaw permits network‑based compromise by an attacker with minimal privileges. The likely attack path involves an HTTP request to the BI Search endpoint, exploiting the improper access control to read data. The potential for data exposure across the system makes the threat significant even if the vulnerability is not currently exploited in the wild.
OpenCVE Enrichment