Impact
A flaw in the Analytics Web General component of Oracle Business Intelligence Enterprise Edition allows an attacker to execute arbitrary code without authentication, potentially compromising the entire system. The vulnerability can lead to full takeover of the platform, exposing all stored data, and allowing the attacker to modify or delete critical information. This impact affects confidentiality, integrity, and availability of the deployed BI service.
Affected Systems
Oracle Corporation’s Oracle Business Intelligence Enterprise Edition 12.2.1.4.0 is affected. No other versions or products have been reported as vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 8.1 indicates high severity, with non‑privileged access required and the requirement to interact over the network via HTTP. The EPSS score is below 1%, suggesting that active exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path requires an unauthenticated attacker to send a specially crafted request to the Analytics Web General endpoint, which can trigger the execution of arbitrary code, resulting in a total system compromise.
OpenCVE Enrichment