Impact
Oracle BI Publisher contains a weakness in its BI Platform Security component that enables a low‑privileged attacker with network access to compromise the system over HTTP. When successfully exploited, an attacker can create, delete, or modify critical data that is normally protected, allowing unauthorized access to all data available through the publisher. The flaw requires the attacker to be able to interact with a user other than themselves in order to gain the necessary privileges, indicating that user interaction is a prerequisite for exploitation.
Affected Systems
Oracle Corporation’s BI Publisher product is affected in the following versions: 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0.
Risk and Exploitability
The identified vulnerability carries a high severity score of 8.7 on the CVSS 3.1 scale, with a low exploit probability indicated by an EPSS score of less than 1 %. Although it is not listed in CISA’s KEV catalog, the high impact on confidentiality and integrity means that any successful attack can lead to significant data tampering or disclosure. The attack can be performed over the network via HTTP from any low‑privileged host, but requires human interaction – typically an injected request or malicious link clicked by an authorized user – and could also affect other Oracle Analytics components due to the scope change.
OpenCVE Enrichment