Impact
A local vulnerability in the Oracle Business Intelligence Enterprise Edition machine learning component allows an attacker with low privileges who can log on to the underlying infrastructure to gain full control of the BI system, compromising confidentiality, integrity, and availability. The flaw is exploitable in versions 8.2.0.0.0 and 26.01.0.0.0, enabling a takeover of the application.
Affected Systems
Oracle Corporation’s Business Intelligence Enterprise Edition, versions 8.2.0.0.0 and 26.01.0.0.0, are affected. This includes the machine learning component of Oracle Analytics running in enterprise deployments.
Risk and Exploitability
The CVSS v3.1 score of 7.8 and AV:L, AC:L, PR:L, UI:N vector indicate a high‑severity local privilege attack that requires only low privilege. The EPSS score of < 1% suggests that widespread exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, once exploited it gives the attacker full control over the BI environment and can be used to exfiltrate sensitive data, disrupt services, or pivot to other systems on the network. The attack scenario likely involves the attacker logging into a host that runs the BI service, using the vulnerability to bypass normal authorization checks and take over the application.
OpenCVE Enrichment