Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Service Administration UI). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Full System Compromise
Action: Patch Immediately
AI Analysis

Impact

The vulnerability resides in the Service Administration UI of Oracle Business Intelligence Enterprise Edition. An attacker with low privileges can exploit the flaw over a network connection via HTTP. Successful exploitation grants full control over the Oracle BI instance, allowing the attacker to read, modify or delete data and disrupt services, thereby compromising confidentiality, integrity, and availability.

Affected Systems

Affected is Oracle Business Intelligence Enterprise Edition, version 12.2.1.4.0, a component of Oracle Analytics. The flaw is limited to the Service Administration UI.

Risk and Exploitability

The CVSS base score of 8.8 indicates high severity. The EPSS score is below 1%, suggesting a low current exploitation likelihood. The vulnerability is not listed in CISA's KEV catalog. Nevertheless, the attack vector is network-based via HTTP and only requires a low privileged attacker, which means organizations running the unpatched edition should treat this as a significant threat and apply the vendor patch as soon as possible.

Generated by OpenCVE AI on September 20, 2026 at 08:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Business Intelligence Enterprise Edition 12.2.1.4.0
  • Restrict HTTP access to the Service Administration UI to trusted hosts or subnets only
  • Enable and review audit logs for anomalous authentication or administrative activity

Generated by OpenCVE AI on September 20, 2026 at 08:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Exploitable Oracle BI Service Administration UI Vulnerability

Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title HTTP Remote Access Enables Full Compromise of Oracle Business Intelligence Enterprise Edition
Weaknesses CWE-284
CWE-287

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title HTTP Remote Access Enables Full Compromise of Oracle Business Intelligence Enterprise Edition
Weaknesses CWE-284
CWE-287

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Service Administration UI). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle business Intelligence
CPEs cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*
Vendors & Products Oracle
Oracle business Intelligence
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Business Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:27.486Z

Reserved: 2026-08-31T15:40:57.351Z

Link: CVE-2026-83301

cve-icon Vulnrichment

Updated: 2026-09-17T13:00:09.201Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:42.980

Modified: 2026-09-17T14:17:40.597

Link: CVE-2026-83301

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:15:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management