Impact
The vulnerability in Oracle Business Intelligence Enterprise Edition allows a high‑privileged attacker with network access via HTTP to fully compromise the system. Code execution or similar compromise can lead to loss of confidentiality, integrity, and availability. The CVSS score of 7.2 reflects these impacts. The description states that the attack is easily exploitable and requires high privileges but no user interaction.
Affected Systems
Oracle Corporation’s Oracle Business Intelligence Enterprise Edition, version 26.01.0.0.0, is the only affected product. The flaw resides in the Analytics Web Answers component of Oracle Analytics.
Risk and Exploitability
The attack vector is inferred to be the public Web Answers interface, accessed over the network. The vulnerability is classified as AV:N/AC:L/PR:H, indicating that an attacker with high privileges can exploit it from any network location without additional user interaction. The EPSS score of less than 1% indicates a low probability of exploitation and is not negligible. The CVSS base score of 7.2 and the absence from CISA’s KEV list suggest moderate to high risk. If exploited, the attacker could control the BI Enterprise Edition environment, potentially exposing all underlying analytics data and services.
OpenCVE Enrichment