Impact
Oracle Business Intelligence Enterprise Edition contains a flaw in its Analytics Web General component that fails to enforce proper authentication checks. The weakness is identified as CWE‑284 (Improper Authentication). This flaw allows an unauthenticated attacker who can reach the system over HTTP to create, delete, or modify critical data and to induce a partial denial of service. The vulnerability also permits unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data.
Affected Systems
Oracle Corporation’s Oracle Business Intelligence Enterprise Edition is affected. The vulnerable versions are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0.
Risk and Exploitability
The CVSS 3.1 base score of 8.9 indicates high severity with confidentiality, integrity, and availability impacts. The EPSS score of less than 1 % indicates a very low but non‑zero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers can reach the affected servers over HTTP (network access) and, without authentication, achieve unauthorized data manipulation or a partial denial‑of-service, potentially exposing all data the application can access.
OpenCVE Enrichment