Impact
The vulnerability in Oracle Business Intelligence Enterprise Edition allows an attacker who can reach the system over HTTP to bypass authentication checks and gain full control of the application. Based on the description, it is inferred that an attacker, after gaining control, could read, modify, or delete any data and disrupt services, though the description does not explicitly state these effects. The high CVSS score reflects full confidentiality, integrity, and availability compromise.
Affected Systems
Oracle Business Intelligence Enterprise Edition version 12.2.1.4.0 is affected. All installations of this version are vulnerable until a patch or upgrade is applied.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, and while the EPSS score is very low (<1%), the vulnerability is still exploitable from the network using standard HTTP traffic. Attackers who can reach the BI server can compromise the BI environment, gaining full control. The vulnerability is not listed in CISA KEV, but the high impact and easy exploitation make it a priority.
OpenCVE Enrichment