Impact
An attacker with low privileges who can reach the system over HTTP can exploit a flaw in Oracle BI Publisher to gain unauthorized access to critical or all data that the application can serve, and can also trigger a partial denial of service. The vulnerability allows the attacker to read confidential data and disrupt service availability without needing user interaction.
Affected Systems
Oracle BI Publisher version 8.2.0.0.0, 12.2.1.4.0 and 26.1.0.0.0 are affected. Only Oracle BI Publisher is listed as impacted; the flaw may extend to other Oracle Analytics components due to scope change.
Risk and Exploitability
The CVSS 3.1 base score of 8.5 indicates high severity, with confidentiality and availability impacts. EPSS score is < 1%, and the flaw is not listed in the CISA KEV catalog. Defined as a network‑based, low‑privilege exploit (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L), an attacker can remotely compromise the system with minimal effort, making it easily exploitable for obtaining data or partially shutting down the application.
OpenCVE Enrichment