Impact
The Platform Security component in Oracle Business Intelligence Enterprise Edition is vulnerable to a locally exploitable flaw that permits a low‑privileged attacker with access to the hosting infrastructure to compromise the entire BI instance. This flaw is a privilege‑escalation vulnerability (CWE‑269). Once the vulnerability is exercised, the attacker can gain control of the application, resulting in confidentiality, integrity, and availability loss for the BI data and services.
Affected Systems
The vulnerability affects Oracle Corporation's Oracle Business Intelligence Enterprise Edition product, specifically the 8.2.0.0.0 and 26.01.0.0.0 releases. Only these versions are currently documented as impacted; newer or older releases are not reported to be affected.
Risk and Exploitability
With a CVSS score of 7.8 and an EPSS below 1%, the risk is moderate but concerns the potential for local privilege escalation. The vulnerability is not listed in the CISA KEV catalog, implying no current exploitation in the wild. The attack vector is local; an attacker must first log on to the server hosting the BI instance, a low complexity and low privilege scenario that can be mitigated by restricting local access or applying the vendor fix.
OpenCVE Enrichment