Impact
The vulnerability in Oracle BI Publisher enables a low‑privileged attacker with network access to the SOAP interface to perform unauthorized addition, deletion, or alteration of data stored by the application. This improper access control flaw also permits reads of a subset of the data. The effects are a compromise of confidentiality and integrity for the reports and documents managed by BI Publisher.
Affected Systems
Affected products are Oracle BI Publisher from Oracle Corporation. Vulnerable releases are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Workforces running any of these versions are exposed.
Risk and Exploitability
The CVSS 3.1 base score of 8.5 indicates a high severity with significant confidentiality and integrity impact. The EPSS score of less than 1% suggests a current low probability of exploitation, and the issue is not listed in CISA’s KEV catalog. The likely attack vector is over the network via the SOAP services, requiring only low privileges. A successful exploit could lead to unauthorized data modification or read and may affect other Oracle Analytics components that interact with BI Publisher due to the scope change.
OpenCVE Enrichment