Impact
The flaw resides in the BI Platform Security component of Oracle Business Intelligence Enterprise Edition, allowing a low‑privileged attacker with network access via HTTP to bypass standard authentication controls. Successful exploitation enables creation, deletion, or modification of access rights to critical data, effectively granting the attacker unauthorized entry to all data managed by the platform. The vulnerability falls under CWE‑284, reflecting a broken access control weakness, and is rated with a CVSS 3.1 base score of 8.2, indicating high severity with significant confidentiality and integrity impacts.
Affected Systems
Oracle Corporation’s Oracle Business Intelligence Enterprise Edition (Oracle Analytics) is affected. The problematic releases are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. The description notes a potential scope change that could also impact additional products if the BI platform is compromised, but no other specific product versions are listed.
Risk and Exploitability
The high CVSS score of 8.2 indicates a severe threat to confidentiality and integrity, yet the EPSS score of <1% shows low but nonzero exploitation probability. The vulnerability is not catalogued in the CISA KEV list, implying no known active exploits. The likely attack vector is network‑based HTTP targeting the BI platform, which only requires low‑privileged credentials. Because the affected instance is exposed to a network, organizations must weigh the low exploitation likelihood against the significant damage potential that a successful breach could inflict.
OpenCVE Enrichment