Impact
Oracle BI Publisher is vulnerable to an un‑authenticated flaw that can be exploited over HTTP. The flaw permits an attacker to read critical data and in some instances to insert, update, or delete data that the application exposes, as well as to trigger a limited denial of service. These capabilities represent a serious compromise of confidentiality, integrity, and availability, as reflected by the CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).
Affected Systems
The affected product is Oracle BI Publisher from Oracle Corporation. Vulnerable releases include version 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Deployments running any of these versions are at risk.
Risk and Exploitability
With a CVSS base score of 8.6 and an EPSS score below 1%, the vulnerability is highly impactful but currently deemed unlikely to be widely exploited. It is not listed in the CISA KEV catalog. The attack vector is likely to be remote network access via HTTP, requiring no credentials. Given the un‑authenticated nature of the exploit, a threat actor can perform the described actions without prior access, making it a critical issue for exposed instances.
OpenCVE Enrichment