Impact
A local, low‑privilege attacker who can log on to the infrastructure where Oracle Business Intelligence Enterprise Edition runs can exploit a flaw in the Platform Security component. The vulnerability allows the attacker to fully compromise the BI installation, gaining confidentiality, integrity, and availability damage as indicated by the CVSS vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The flaw is a CWE-284 vulnerability, indicating an Improper Access Control weakness. The impact extends to all data accessed through the BI service and to any integrated applications.
Affected Systems
Oracle Corporation’s Oracle Business Intelligence Enterprise Edition, version 26.01.0.0.0, is affected. No other versions or products are listed as vulnerable.
Risk and Exploitability
The CVSS base score of 7.8 classifies this flaw as high severity. The EPSS score of < 1% indicates a low but nonzero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it may not be widely exploited yet. However, because the attack vector is local and requires only low privileges, an attacker who has any foothold on the host can potentially gain full control of the BI server. Management and auditing controls should consider the possibility of collateral damage to other services on the host.
OpenCVE Enrichment