Impact
The vulnerability resides in the BI Search component of Oracle Business Intelligence Enterprise Edition. An attacker with low privileged access to the machine that hosts the BI service can exploit this flaw to achieve local privilege escalation, ultimately compromising the entire application and leading to loss of confidentiality, integrity, and availability. The flaw is an improper access control and privilege management issue, reflected in CWE-269.
Affected Systems
Oracle Business Intelligence Enterprise Edition versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 are affected. The product is delivered by Oracle Corporation and is widely deployed in enterprise deployments that rely on the BI Search functionality.
Risk and Exploitability
CVSS v3.1 base score is 7.8, with a vector of AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H indicating that the vulnerability can be exploited locally by an attacker who has low privileges. The EPSS score is below 1%, suggesting a low probability of current exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, because the flaw grants full control over the affected application, it warrants prioritized remediation.
OpenCVE Enrichment