Impact
Vulnerability in Oracle BI Publisher’s BI Platform Security component permits a low‑privilege attacker who can reach the service over HTTP to gain unauthorized access to data. The flaw allows the attacker to bypass authentication controls, resulting in full or partial exposure of critical BI Publisher content.
Affected Systems
Oracle Corporation’s Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0 are impacted. The vulnerability may also affect other related Oracle Analytics components due to a scope change.
Risk and Exploitability
With a CVSS v3.1 base score of 7.7 and an EPSS probability of less than 1%, the vulnerability is moderately severe yet not highly likely to be exploited. It is exploitable via the public HTTP interface by an adversary with network access, and successful exploitation can lead to unauthorized data access across all BI Publisher instances.
OpenCVE Enrichment