Impact
An unauthorized low‑privileged attacker who can reach the Oracle BI Publisher Web Service API can send crafted SOAP requests that bypass improperly enforced access controls (CWE‑284). The flaw permits the attacker to fully compromise the application, leading to unauthorized data disclosure, modification, and the ability to disrupt service availability.
Affected Systems
Oracle BI Publisher version 8.2.0.0.0 and 26.1.0.0.0, distributed by Oracle Corporation.
Risk and Exploitability
The vulnerability scores a CVSS 3.1 Base Score of 9.9, indicating critical severity. The EPSS score is less than 1 %, and the condition is not listed in the CISA KEV catalog, suggesting a low probability of widespread exploitation at present. However, the high potential impact on confidentiality, integrity, and availability, coupled with the low attack‑vector complexity and a single low‑privilege credential requirement, warrants prompt action, especially since scope changes may affect additional products.
OpenCVE Enrichment