Impact
Oracle BI Publisher’s SOAP interface exposes a flaw that allows a low‑privileged attacker with network access to create, delete or modify critical data and to trigger complete application hangs or crashes. The vulnerability is identified in the BI Platform Security component and occurs when SOAP requests bypass sufficient access controls. The impact is direct loss of data integrity and application availability, potentially affecting all data exposed through Oracle BI Publisher.
Affected Systems
Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0 are affected. Any deployment that has the SOAP API exposed to external networks is susceptible to these attacks.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 reflects severe integrity and availability consequences. The EPSS score of <1% indicates a very low probability of exploitation in the current threat environment, but the vulnerability is not listed in CISA’s KEV catalog, so the potential business impact remains significant. The likely attack vector is over the network via crafted SOAP requests; the description suggests that low‑privilege credentials or even no authentication are sufficient, although this is inferred rather than explicitly documented.
OpenCVE Enrichment