Impact
The vulnerability resides in the Analytics Web General component of Oracle Business Intelligence Enterprise Edition. It permits a low-privileged attacker that can reach the SOAP interface over the network to bypass normal access controls and gain full control over the BI system. Successful exploitation would allow complete takeover of the application, compromising confidentiality, integrity, and availability of all underlying data and services. The weakness corresponds to Configuration or Permission Errors (CWE-269).
Affected Systems
Affected deployments include Oracle Business Intelligence Enterprise Edition from Oracle Corporation, specifically versions 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. All installations running these releases without the vendor’s patch remain vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates high severity. The EPSS score is less than 1 percent, suggesting that exploitation opportunities are currently low, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Nevertheless, the attack vector is straightforward: an attacker with network connectivity to the SOAP endpoint can submit a crafted request that bypasses normal access controls and grants them unrestricted authority over the BI system.
OpenCVE Enrichment