Impact
A vulnerability exists in Oracle Business Intelligence Enterprise Edition that allows a low‑privileged user who has logged onto the underlying infrastructure to compromise the BI application. The flaw is easily exploitable and, if successful, gives the attacker control over the BI system, allowing disclosure, modification, and denial of services to the application and its data.
Affected Systems
Oracle Corporation’s Oracle Business Intelligence Enterprise Edition version 12.2.1.4.0 is affected. The specific component impacted is FNDN. No other versions or editions were mentioned as vulnerable.
Risk and Exploitability
The CVSS 3.1 score of 7.8 indicates moderate to high severity, with complete confidentiality, integrity, and availability impacts and no user interaction required. The EPSS score is below 1%, suggesting current exploitation attempts are rare, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, requiring only that the attacker have basic user‑level access to the host where Oracle BI runs.
OpenCVE Enrichment