Impact
A flaw in the BI Platform Security component of Oracle BI Publisher allows an attacker with low system privileges and network access to exploit the SOAP interface. By doing so the attacker can gain unauthorized read access to critical data and, in some cases, execute write operations - update, insert, or delete - on data exposed by the application. The vulnerability is characterized by an AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N vector, indicating that network-based exploitation leads to a significant impact on confidentiality and a moderate impact on integrity.
Affected Systems
The affected product is Oracle BI Publisher, part of Oracle Analytics. Supported versions that are vulnerable are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Any deployment using these versions is susceptible to the described exploitation path.
Risk and Exploitability
The CVSS base score of 8.5 reflects a high level of severity, while the EPSS score of less than 1% suggests a low probability of current exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, yet the potential for scope change means that related Oracle Analytics products could also be impacted. Attacks require only low privileged credentials and SOAP access, making the attack vector readily achievable for adversaries with network presence, though the overall exploitation likelihood remains relatively low.
OpenCVE Enrichment