Impact
A vulnerability in Oracle BI Publisher’s BI Platform Security component enables an attacker with low privileges and network access via HTTP to create, delete, or modify data, obtain unauthorized access to critical or all data, and induce a partial denial of service. The weakness permits the attacker to perform actions that impact confidentiality, integrity, and availability of the application.
Affected Systems
Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 are affected. This refers to the Oracle Analytics product line integrated with BI Publisher.
Risk and Exploitability
The vulnerability carries a CVSS Base Score of 8.3 and an EPSS score of less than 1%, indicating that exploitation is unlikely but still possible. The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L) suggests remote exploitation over the network, low technical skill required, and a moderate impact on availability. It is not listed in CISA’s KEV catalog, and no official workaround or exploit is publicly known at this time. The likely attack path is a simple HTTP request exploiting insufficient access control checks, enabling unauthorized data manipulation and service degradation.
OpenCVE Enrichment