Impact
The flaw is an access control bypass in the BI Search component of Oracle Business Intelligence Enterprise Edition. It allows an attacker with low privileges and basic HTTP network access to create, delete, or modify data, to read all data exposed by the system, and to trigger a partial denial of service. The weakness is a classic access‑control failure (CWE‑284) that results in full compromise of confidentiality, integrity, and some availability of the BI system.
Affected Systems
Oracle Business Intelligence Enterprise Edition version 12.2.1.4.0, delivered by Oracle Corporation as part of the Enterprise Analytics suite, is affected. The vulnerability resides in the BI Search module of this product.
Risk and Exploitability
The CVSS base score of 8.3 highlights significant severity. The EPSS score is below 1%, suggesting that widespread exploitation is currently unlikely, and the vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit the flaw by sending HTTP requests to the BI Search endpoint without user interaction; only a low level of privilege is required to trigger the access‑control bypass, making it reachable by many users in the network.
OpenCVE Enrichment