Impact
This vulnerability is located in the Platform Security component of Oracle Business Intelligence Enterprise Edition. An unauthenticated attacker that has logged on to the same infrastructure where the BI service runs can exploit it. The flaw allows the attacker to take over the BI system, resulting in full confidentiality, integrity, and availability compromise of the application. The vulnerability requires human interaction from a person other than the attacker, implying that an insider or a co‑operator must provide some user‑mode input or consent for the exploit to succeed. The impact is total loss of control over the affected BI instance.
Affected Systems
Affected releases are Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. These versions correspond to the product releases identified by the provided CPE strings. Administrators should verify that their installations match any of these version identifiers to determine exposure.
Risk and Exploitability
The CVSS 3.1 base score is 7.8, reflecting high confidentiality, integrity, and availability impact with local attack, low required privileges, and required user interaction. The EPSS score is less than 1 %, indicating a very low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires an unauthenticated attacker who has logged on to the infrastructure where the BI service runs and must convince a user to perform a required action. If achieved, the attacker gains full control of the BI instance.
OpenCVE Enrichment