Impact
A vulnerability in Oracle Business Intelligence Enterprise Edition allows a low‑privileged attacker with network access via HTTP to compromise the platform. Successful exploitation can lead to the creation, deletion, or modification of data, unauthorized retrieval of all accessible data, and the ability to cause a partial denial of service. The CVSS 3.1 Base Score of 8.3 indicates significant confidentiality and integrity impact with a moderate availability impact.
Affected Systems
Oracle Business Intelligence Enterprise Edition 12.2.1.4.0 is the affected product version. This version is distributed as part of Oracle Analytics under the BI Platform Security component.
Risk and Exploitability
The high CVSS score combined with the availability of an HTTP‑based attack vector means the risk to systems is considerable. The EPSS score is < 1%, indicating a very low probability that the vulnerability is actively exploited. The vulnerability is not listed in the CISA KEV catalog at present. The scenario relies on a low‑privileged attacker gaining network access, so any exposed instance of the BI platform poses a tangible threat.
OpenCVE Enrichment