Impact
A vulnerability in the Machine Learning component of Oracle Business Intelligence Enterprise Edition permits local privilege escalation. The flaw lets an attacker who can log on to the infrastructure where the BI service runs gain full control over the application, compromising confidentiality, integrity, and availability of the BI instance.
Affected Systems
Oracle Business Intelligence Enterprise Edition versions 8.2.0.0.0 and 26.01.0.0.0 are affected. The issue resides specifically within the Machine Learning subsystem of these products.
Risk and Exploitability
The CVSS v3.1 base score of 7.8 coupled with vector AV:L/AC:L/PR:L/UI:N indicates a high‑severity local attack that requires only low privileges and no user interaction. Based on the description, the likely attack vector is a user who can log on to the host running the BI service. The EPSS score of <1 % indicates the vulnerability is not widely exploited today, and it is not listed in the CISA KEV catalog. Nonetheless, once exploited, the attacker achieves full control of the BI environment, enabling data exfiltration, denial of service or lateral movement.
OpenCVE Enrichment