Impact
The flaw lies in the Web Service API of Oracle BI Publisher and can be exploited easily by an attacker with network access via HTTP and low privileges. Successful exploitation allows compromise of confidentiality, integrity, and availability, effectively enabling the attacker to take over the application.
Affected Systems
Oracle BI Publisher is impacted in the versions 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0, all part of Oracle Analytics.
Risk and Exploitability
The vulnerability scores a CVSS 3.1 base score of 8.8, indicating high severity. EPSS indicates a very low exploitation probability (< 1 %), and the flaw is not listed in the CISA KEV catalog. The likely attack vector is a network‑based HTTP request to the exposed Web Service API, and since the attacker only needs low privilege, exploitation can occur without elevated rights or user interaction.
OpenCVE Enrichment