Impact
Oracle BI Publisher 12.2.1.4.0 contains a security flaw that allows an attacker with low privileges and network access via HTTP to gain unauthorized access to critical data or all data accessible through the application and to cause a partial denial of service. This results in confidentiality and availability impacts as reflected in the CVSS vector (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L).
Affected Systems
The vulnerability affects Oracle BI Publisher version 12.2.1.4.0 deployed within Oracle Analytics environments. Attackers may also impact other connected Oracle Analytics products due to the indicated scope change.
Risk and Exploitability
The CVSS base score of 8.5 indicates a high severity risk. The EPSS score of less than 1% suggests exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. However, an attacker with low privileges only needs network access to the HTTP interface to potentially read critical data or cause a service interruption.
OpenCVE Enrichment