Impact
A flaw within the Platform Security component of Oracle Business Intelligence Enterprise Edition permits a low‑privileged attacker with network reachability via HTTP to compromise the application. Successful exploitation can lead to complete takeover, exposing confidential data, altering integrity of analytics, and rendering the service unavailable.
Affected Systems
The vulnerability impacts Oracle Corporation’s Oracle Business Intelligence Enterprise Edition, specifically versions 8.2.0.0.0 and 26.01.0.0.0. These are the only releases confirmed to be affected by the flaw.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 illustrates a high risk to confidentiality, integrity, and availability, while the EPSS score of less than 1% indicates a low probability of active exploitation at present. The issue is not listed in the CISA KEV catalog, but the attack vector is a straightforward network HTTP approach that requires only a low‑privileged user account. Given the potential for complete application compromise, organizations should treat this as a high‑priority security issue and apply the vendor’s patch as soon as it becomes available.
OpenCVE Enrichment