Impact
The vulnerability resides in the Platform Security component of Oracle unauthenticated attacker with network access via HTTP can exploit a weakness that permits full compromise of the BI service. Successful exploitation results in complete takeover, giving the attacker full control over the system. The flaw triggers confidentiality, integrity, and availability loss as reflected by the CVSS v3.1 score of 8.1 with impacts on C, I, and A.
Affected Systems
Oracle Business Intelligence Enterprise Edition is impacted in the following releases: 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. These versions provide the context for the vulnerability analysis.
Risk and Exploitability
The CVSS base score of 8.1 classifies this flaw as high severity, but the EPSS score indicates that the probability of exploitation is very low (<1%). It is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. The admission route is likely an unauthenticated HTTP request to the BI service, requiring no user credentials but network connectivity to reach the instance. Once the flaw is triggered, an attacker who is on the same network or has internet exposure to the service could gain full administrative control of the BI platform.
OpenCVE Enrichment