Impact
Oracle BI Publisher version 12.2.1.4.0 contains an easily exploitable vulnerability in the BI Platform Security component that allows a high privileged attacker with network access via HTTP to compromise the system. This vulnerability is related to a privilege and authorization weakness (CWE-269). A successful exploit would result in a full takeover, enabling the attacker to exfiltrate data, tamper with content, and disrupt service, leading to complete loss of confidentiality, integrity, and availability. The CVSS v3.1 base score of 7.2 reflects this high impact scenario.
Affected Systems
The affected system is Oracle BI Publisher 12.2.1.4.0 deployed by Oracle Corporation.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.2, indicating high severity, while the EPSS score of less than 1% suggests a low current probability of exploitation. It is not listed in the CISA KEV catalog. Attackers require network access over HTTP and must already possess high privileges; the exploitation path is network-based and does not require user interaction, making remote compromise feasible but limited to trusted high-privilege users.
OpenCVE Enrichment