Impact
The vulnerability lies in the Authentication and Authorization controls of Oracle Business Intelligence Enterprise Edition's BI Platform Security component. Unauthenticated attackers can send HTTP requests to the exposed interface and obtain data without authenticating. If the attack succeeds, the attacker can read confidential data or, in more severe cases, gain access to all data that the product exposes. This is a confidentiality breach, as the attacker is able to expose information intended for authorized users.
Affected Systems
Oracle Business Intelligence Enterprise Edition, versions 8.2.0.0.0 and 26.01.0.0.0, are affected. Oracle has identified these two release lines as vulnerable in its official advisory.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates a high impact on confidentiality. The EPSS score of < 1% suggests that exploitation attempts are rare at this time, and the vulnerability is not listed in CISA's KEV catalog. Nevertheless, because the flaw allows unauthenticated access via a publicly accessible HTTP endpoint, it poses a significant risk to deployments that expose the BI platform to the network. The likely attack vector is remote HTTP traffic to the vulnerable service.
OpenCVE Enrichment