Impact
A flaw in the Platform Security component of Oracle Business Intelligence Enterprise Edition falls under CWE‑284, Improper Access Control, allowing a high‑privileged attacker with network access via HTTP to gain full control of the system. Successful exploitation results in loss of confidentiality, integrity, and availability of the BI server and can serve as a vector to influence other integrated products. The vulnerability’s CVSS base score of 8.0 indicates a high severity and reflects the potential for complete takeover.
Affected Systems
Oracle Business Intelligence Enterprise Edition, version 26.01.0.0.0. The advisory notes a potential impact on additional products that interact with the BI server, though specific systems are not enumerated.
Risk and Exploitability
The CVSS score of 8.0 signals serious risk, while an EPSS score of less than 1% indicates a very low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires network access to HTTP interfaces and high‑privilege authentication; the changed scope allows influence over other services if the attacker succeeds.
OpenCVE Enrichment