Impact
The vulnerability allows an attacker with low privileges and network access via LDAP to create, delete, or modify critical data within Oracle BI Publisher. As a result the attacker can also gain unauthorized access to all data that the publisher can reach, causing significant confidentiality and integrity damage.
Affected Systems
Affected versions are Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. The product is part of Oracle Analytics and is used to publish reports and data. No other versions are mentioned as affected.
Risk and Exploitability
The CVSS base score of 8.1 indicates high severity. The reported EPSS is less than 1%, suggesting exploitation is not widespread but still possible. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a low‑privileged network user that can reach the LDAP service; the description states such an attacker can exploit the flaw. Exploitation would require network connectivity to the LDAP interface of BI Publisher and no special privileges beyond the low‑privilege account.
OpenCVE Enrichment