Impact
Oracle BI Publisher is vulnerable to an easily exploitable flaw that allows an attacker who already possesses high‑privilege credentials and can reach the HTTP endpoint to compromise the system. The vulnerability can jeopardise confidentiality, integrity and availability, enabling an attacker to effectively takeover the application. The impact may extend beyond the core product and affect other components that rely on the same underlying platform.
Affected Systems
Affected releases are Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. All installations of these versions should be treated as vulnerable until updated.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 classifies this as critical, and the EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation. This vulnerability is not listed in the CISA KEV catalogue. The likely attack vector is network‑based, accessed through HTTP, and requires an attacker to have high‑privilege credentials. Successful exploitation can lead to full takeover of the BI Publisher instance and potentially ancillary products on the same infrastructure.
OpenCVE Enrichment