Impact
This vulnerability resides in the Oracle BI Publisher component of Oracle Analytics. It allows an unauthenticated attacker who can reach the application via HTTP to compromise the system. The attack grants full control, resulting in loss of confidentiality, integrity, and availability. The flaw is classified as authentication bypass (CWE‑287) and improper privilege management (CWE‑306). The likely attack vector is network, specifically HTTP traffic to the BI Publisher service.
Affected Systems
Affected products are Oracle BI Publisher from Oracle Corporation. The specific affected releases are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Other versions are not listed as impacted.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity and the attack surface is remote, unauthenticated, with low attack complexity, no user interaction, and the vulnerability is unscoped. The EPSS score is below 1%, suggesting that mass exploitation is currently low, and it is not listed in the CISA KEV catalog. Nonetheless, the combination of high severity and network reachability means patching should be treated as a high priority, as attackers could still exploit the flaw in targeted campaigns.
OpenCVE Enrichment