Impact
A vulnerability in Oracle Business Intelligence Enterprise Edition’s Presentation Services allows a low‑privileged attacker with network access via SOAP to bypass authentication controls and obtain unauthorized access to critical data. The weakness is exploitable over the network, can be used by an attacker with limited privileges, and expands the scope to other Oracle products, creating a high‑confidentiality breach risk. The CVSS 3.1 vector shows network access, low attack complexity, low privileges, no user interaction, and a changed scope with high confidentiality impact.
Affected Systems
Oracle Business Intelligence Enterprise Edition, versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0.
Risk and Exploitability
The CVSS base score of 7.7 indicates significant severity while the EPSS score of less than 1% suggests a low probability of exploitation at the present time, and the vulnerability is not listed in the CISA KEV catalog. It can be exploited remotely via SOAP, requiring only low privileges and no user interaction, but the impact includes full data exposure for all accounts that can reach the affected service.
OpenCVE Enrichment