Impact
The CVE targets the Web Server component of Oracle BI Publisher. An attacker that can reach the HTTP interface with low privileges can exploit the vulnerability to read or modify data that is normally restricted. The recorded impact includes potential unauthorized access to critical data and the ability to insert, update or delete records. These consequences are reflected in the CVSS vector: high confidentiality impact and low integrity impact, indicating that the flaw primarily allows data exfiltration and some disruptive edits.
Affected Systems
Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0 are affected. These versions are deployed across Oracle Analytics environments, and the vulnerability’s scope change (S:C) means that exploitation can also influence other components of the analytics stack, potentially extending the attack surface beyond the Publisher service.
Risk and Exploitability
The CVSS v3.1 score of 8.5 marks the issue as high severity. The EPSS score of <1% suggests a low probability of widespread public exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the attack vector is remote over HTTP and requires only low system privileges, so an exposed Publisher instance is at risk. Successful exploitation could provide an attacker with read access to sensitive data and limited write capability, which could lead to data corruption or compromise of downstream analytics processes.
OpenCVE Enrichment