Impact
A flaw in Oracle BI Publisher’s SOAP interface, classified as improper access control (CWE‑284) allows an unauthenticated attacker with network access to trigger a full application crash and repeatedly cause hangs, leading to complete denial of service. The same exploited path also grants the attacker the ability to read a subset of the data exposed by BI Publisher and to perform unauthorized insert, update or delete operations on that data, impacting confidentiality, integrity and availability.
Affected Systems
The vulnerability is present in Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0, all of which are part of Oracle Analytics. No other product or version information is provided.
Risk and Exploitability
The CVSS v3.1 base score is 8.6, reflecting high severity. The EPSS score is below 1 %, indicating a low to medium likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attack from the network is inferred as the vector via SOAP, as the description states that the flaw is exploitable over SOAP with unauthenticated network access.
OpenCVE Enrichment