Impact
The vulnerability resides in the Presentation Services component of Oracle Business Intelligence Enterprise Edition. An attacker who has any logon rights on the server can trigger a flaw that, with the aid of a separate user, compromises the entire BI instance. Successful exploitation results in takeover, affecting confidentiality, integrity and availability.
Affected Systems
Oracle Corporation’s Oracle Business Intelligence Enterprise Edition version 12.2.1.4.0 is affected. No other product variants or versions are listed in the advisory.
Risk and Exploitability
The CVSS v3.1 base score is 7.3, indicating high severity. The attack vector is local with low privilege (AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). EPSS <1% shows a very low but non‑zero chance of exploitation in the wild, and the vulnerability is not in the CISA KEV catalog. Despite the low exploitation probability, a user with logon rights can trigger the flaw with another user’s cooperation, so the risk remains significant and urgent patching is warranted.
OpenCVE Enrichment