Impact
The vulnerability allows a low‑privileged attacker with network access to exploit the Oracle BI Publisher SOAP Web Service API, enabling unauthorized creation, deletion or modification of data as well as repeated crashes that result in denial of service. The flaw arises from inadequate access control and validation within the API, producing significant integrity and availability impacts without affecting confidentiality.
Affected Systems
Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0 are affected. These versions are part of Oracle Analytics and are accessible via SOAP endpoints if exposed over the network.
Risk and Exploitability
The CVSS 3.1 base score of 8.1, combined with a low exploitation complexity and a requirement for only local privileges, indicates a high severity. The EPSS score is below 1 %, which suggests a low probability of widespread exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, because the actor only needs network access to the SOAP service, the attack vector is likely an unauthenticated or loosely authenticated SOAP request, making it deployable in multiple environments without sophisticated prerequisites.
OpenCVE Enrichment