Impact
The vulnerability in Oracle Business Intelligence Enterprise Edition allows an unauthenticated attacker who can reach the system over HTTP to access data that should be protected by authentication. The flaw effectively bypasses the authentication mechanism, enabling the attacker to read any data exposed by the BI instance, thereby compromising confidentiality and potentially exposing sensitive business information.
Affected Systems
The vulnerabilities affect Oracle Corporation’s Oracle Business Intelligence Enterprise Edition in the 8.2.0.0.0 and 26.01.0.0.0 releases. The flaw resides in the Analytics Server component of the product. Only these versions are known to be impacted.
Risk and Exploitability
Based on the description, it is inferred that the attack vector is over HTTP network access. The flaw has a CVSS 3.1 base score of 7.5, indicating high risk. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the issue over the network via a standard HTTP connection without any prior authentication. Given the simplicity of the attack path, the vulnerability is considered readily exploitable in environments where the BI server is exposed to the internet or an untrusted subnet.
OpenCVE Enrichment