Impact
The Oracle Business Intelligence Enterprise Edition product contains a vulnerability in the Platform Security component that permits a local attacker who has logged on with low privileges to compromise the application. The flaw can lead to a full takeover of the system. The CVSS 3.1 score of 7.0 reflects severe confidentiality, integrity, and availability impacts.
Affected Systems
Affected systems include Oracle Business Intelligence Enterprise Edition version 26.01.0.0.0. The vulnerability is specific to that version and the Platform Security module. No other releases were noted as impacted in the advisory.
Risk and Exploitability
The exploit requires local access and no public exploitation has been reported. The EPSS score of less than 1% indicates a low probability of attack, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the high severity of the CVSS score warrants prompt remediation to prevent potential takeover by an internal threat actor.
OpenCVE Enrichment