Impact
The vulnerability resides in the Service Administration UI of Oracle Business Intelligence Enterprise Edition. An attacker with low privileges can exploit the flaw over a network connection via HTTP. Successful exploitation grants full control over the Oracle BI instance, allowing the attacker to read, modify or delete data and disrupt services, thereby compromising confidentiality, integrity, and availability.
Affected Systems
Affected is Oracle Business Intelligence Enterprise Edition, version 12.2.1.4.0, a component of Oracle Analytics. The flaw is limited to the Service Administration UI.
Risk and Exploitability
The CVSS base score of 8.8 indicates high severity. The EPSS score is below 1%, suggesting a low current exploitation likelihood. The vulnerability is not listed in CISA's KEV catalog. Nevertheless, the attack vector is network-based via HTTP and only requires a low privileged attacker, which means organizations running the unpatched edition should treat this as a significant threat and apply the vendor patch as soon as possible.
OpenCVE Enrichment