Impact
The vulnerability resides in the Platform Security component of Oracle Business Intelligence Enterprise Edition, allowing an attacker with low privileges who can reach the system over HTTP to execute arbitrary code on the server and potentially take full control. Successful exploitation results in a comprehensive compromise of confidentiality, integrity, and availability for data and services exposed by the BI platform.
Affected Systems
Affected system: Oracle Business Intelligence Enterprise Edition (Oracle Analytics) version 12.2.1.4.0. The CVE notes that the scope may impact additional Oracle products, but the primary target is the specified BI edition.
Risk and Exploitability
The base CVSS score of 9.9 indicates critical severity. An EPSS score below 1% suggests that current exploitation rates are low, yet the vulnerability remains highly actionable. It is not yet listed in CISA KEV. The likely attack vector is remote HTTP traffic with low privilege, where an attacker can send crafted requests from an external network to trigger the flaw without authentication or elevated rights.
OpenCVE Enrichment