Description
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential takeover of Oracle BI Publisher with confidentiality, integrity, and availability loss
Action: Assess Impact
AI Analysis

Impact

Oracle BI Publisher version 12.2.1.4.0 contains an easily exploitable vulnerability in the BI Platform Security component that allows a high privileged attacker with network access via HTTP to compromise the system. This vulnerability is related to a privilege and authorization weakness (CWE-269). A successful exploit would result in a full takeover, enabling the attacker to exfiltrate data, tamper with content, and disrupt service, leading to complete loss of confidentiality, integrity, and availability. The CVSS v3.1 base score of 7.2 reflects this high impact scenario.

Affected Systems

The affected system is Oracle BI Publisher 12.2.1.4.0 deployed by Oracle Corporation.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.2, indicating high severity, while the EPSS score of less than 1% suggests a low current probability of exploitation. It is not listed in the CISA KEV catalog. Attackers require network access over HTTP and must already possess high privileges; the exploitation path is network-based and does not require user interaction, making remote compromise feasible but limited to trusted high-privilege users.

Generated by OpenCVE AI on September 20, 2026 at 08:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict external HTTP access to the Oracle BI Publisher service by applying firewall rules or VPN so that only trusted networks can reach it.
  • Enforce HTTPS and strong authentication for the BI Publisher web interface and disable unnecessary HTTP ports.
  • Monitor application logs and network traffic for suspicious activity related to BI Publisher exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 08:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title High Privilege Takeover of Oracle BI Publisher via HTTP
Weaknesses CWE-285

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title High Privilege Takeover of Oracle BI Publisher via HTTP
Weaknesses CWE-269
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle bi Publisher
CPEs cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bi Publisher
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Bi Publisher
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:37.427Z

Reserved: 2026-08-31T15:40:57.351Z

Link: CVE-2026-83298

cve-icon Vulnrichment

Updated: 2026-09-17T13:00:16.790Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:42.643

Modified: 2026-09-17T14:17:40.360

Link: CVE-2026-83298

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:15:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management