Impact
Vulnerability in Oracle Business Intelligence Enterprise Edition's Presentation Services component allows low‑privileged attackers with network access to exploit SOAP calls. Successful exploitation can lead to full takeover of the BI platform, compromising confidentiality, integrity, and availability, which aligns with the CVSS vector of AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H. The bug involves improper privilege management, as indicated by CWE-269.
Affected Systems
Oracle Business Intelligence Enterprise Edition of Oracle Analytics, versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 are affected. No sub‑version specificity beyond these main release numbers is reported.
Risk and Exploitability
CVSS 3.1 base score of 7.5 indicates high severity. EPSS score below 1% suggests limited exploitation probability. The vulnerability is not listed in CISA KEV. The open SOAP interface, combined with a low‑privilege requirement, suggests that internal actors with network access could target the endpoint. Based on how this vulnerability is described, it is inferred that an attacker first must discover an exposed SOAP endpoint and then submit a malicious payload, after which remote code execution could occur.
OpenCVE Enrichment