Impact
The vulnerability exists in the Security component of Oracle BI Publisher, allowing an attacker to execute unauthorized read, write, or delete actions on data that should be protected. Successful exploitation results in a confidentiality breach by providing full access to all data accessible by the publisher and an integrity impact through the ability to update, insert, or delete data. The weakness is a lack of proper access control, as described by the CVE description and the CVSS vector.
Affected Systems
The affected products are Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Users running these specific builds and exposing them to HTTP traffic are within scope, with no other versions or components listed as vulnerable.
Risk and Exploitability
The CVSS base score of 8.5 indicates high severity, with a high confidentiality impact and a low integrity impact. The scope change allows the impact to extend beyond the initially compromised environment. The EPSS score is below 1%, indicating a very low but non-zero probability of exploitation in the wild. The likelihood of attack is via direct HTTP traffic from a low-privileged attacker with network access, exploiting weak access control to gain unauthorized read, write, or delete capabilities over Oracle BI Publisher data.
OpenCVE Enrichment