Impact
Oracle BI Publisher, part of Oracle Analytics, contains a vulnerability that allows a low‑privileged attacker with network connectivity via HTTP to retrieve critical data. The flaw results in unauthorized access to all data available through the BI Publisher instance and is a high‑severity access control weakness.
Affected Systems
Affected products include Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. These versions are components of Oracle E‑Business Suite and may run on a variety of operating systems; any deployment that remains in the vulnerable configuration is at risk.
Risk and Exploitability
The CVSS 3.1 base score of 7.7 indicates a moderate to high severity, while the EPSS score of less than 1% indicates a low probability of widespread exploitation in the near term. The vulnerability is not listed in CISA’s KEV catalog, meaning it has not yet been observed in the wild, yet the low privilege requirement and network access route keep the risk notable for systems exposed to the public Internet. Based on the description, attackers could send crafted HTTP requests to the BI Publisher service to retrieve or alter data accessible through that instance.
OpenCVE Enrichment