Impact
The vulnerability lies in the Platform Security component of Oracle Business Intelligence Enterprise Edition, allowing a local attacker who can log on to the underlying infrastructure to compromise the product and result in a complete takeover, with full access to the system’s data, configuration and services availability.
Affected Systems
Affected systems include Oracle Corporation’s Oracle Business Intelligence Enterprise Edition, specifically versions 8.2.0.0.0 and 26.01.0.0.0, as identified in the CNA and CPE strings.
Risk and Exploitability
The CVSS base score of 7.8 indicates significant impact with high confidentiality, integrity and availability effects; the EPSS score of less than 1% suggests low current exploitation likelihood, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector requires local access (AV:L) with low complexity, low privilege, and no user interaction, indicating that low‑privileged users with logon rights can exploit the flaw, making it a high‑risk local privilege escalation that could enable full control of the Oracle BI instance if successful.
OpenCVE Enrichment