Impact
The flaw lies within the BI Platform Security component of Oracle BI Publisher. An attacker who can reach the SOAP endpoints with low‑privileged credentials can send specially crafted requests that exploit a weakness, potentially compromising confidentiality, integrity, and availability of the entire BI Publisher instance. This vulnerability can enable a full takeover of the system. Based on the description, it is inferred that the attacker could perform actions typically protected by the application’s access controls, though the CVE text does not explicitly state a bypass.
Affected Systems
Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0 are affected. These products are part of Oracle Analytics and are commonly deployed to deliver enterprise reporting. When exposed to a network, they present SOAP endpoints that can be accessed by attackers with low‑privileged credentials.
Risk and Exploitability
Earning a CVSS v3.1 base score of 8.8, the issue is classified as high severity. The EPSS score of less than 1% indicates a low current likelihood of exploitation, but because the flaw can be triggered remotely via standard SOAP traffic and only requires low privileges, the potential impact remains significant. The vulnerability is not listed in the CISA KEV catalog, so there are currently no known large‑scale attacks reported.
OpenCVE Enrichment