Impact
The vulnerability lies in the Platform Security component of Oracle Business Intelligence Enterprise Edition. An attacker who obtains high‑privilege credentials and can reach the platform over HTTP may exploit the flaw, enabling a complete compromise of the BI platform. The impact includes loss of confidentiality, integrity, and availability, effectively allowing the attacker to take full control of the system. This flaw is classified as a privilege escalation and broken access control weakness.
Affected Systems
Oracle Business Intelligence Enterprise Edition version 26.01.0.0.0 is affected. No other products or versions are currently identified.
Risk and Exploitability
The CVSS v3.1 base score of 7.2 indicates high severity with significant impacts on confidentiality, integrity and availability. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not yet listed in the CISA KEV catalog. However, because the attacker must have high‑privilege credentials and network reachability over HTTP, the risk remains significant, and the potential for a full platform takeover warrants prompt remediation.
OpenCVE Enrichment