Impact
This vulnerability resides in the BI Search component of Oracle Business Intelligence Enterprise Edition. An attacker who has only low privileges and network access over HTTP can exploit a flaw that allows the compromise of the BI server. The successful exploitation gives the attacker control over the BI server, leading to loss of confidentiality, integrity, and availability of business intelligence data and services. The description explicitly states that the potential outcome is takeover of the BI Enterprise Edition, underscoring the severity of the impact.
Affected Systems
Oracle Business Intelligence Enterprise Edition is affected in the following releases: 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. These versions are related to Oracle Analytics and are publicly disclosed as vulnerable.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high‑severity vulnerability with significant impact on all core security properties. The EPSS score is below 1%, suggesting that observed exploitation is currently rare, but this does not eliminate future risk. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector requires network access over HTTP and an attacker must have only low privileges; no additional authentication or local privileges are required.
OpenCVE Enrichment