Impact
The vulnerability resides in the installation component of Oracle Business Intelligence Enterprise Edition and permits a local attacker—one who already has a user account on the underlying infrastructure—to elevate privileges. An attacker can execute commands or modify configuration files that roll over the protected business intelligence service, thereby gaining both confidentiality, integrity, and availability control over the product. The impact is that the entire BI environment can be taken over, allowing unrestricted data access and manipulation.
Affected Systems
The affected product is Oracle Business Intelligence Enterprise Edition, version 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0, as distributed by Oracle Corporation. All installations of these versions that have not applied the vendor’s patch are exposed.
Risk and Exploitability
The CVSS 3.1 base score of 7.8 indicates a high‑severity vulnerability. Its EPSS score of <1% denotes a low probability of exploitation in the wild, and it is not currently listed in CISA’s KEV catalog. Likely exploitation requires physical or local network access to the BI server, making the threat skews toward compromised or poorly fenced environments. Once an attacker achieves local logon, exploitation is trivial and leads to full takeover of the BI software.
OpenCVE Enrichment