Impact
of Oracle BI Publisher and permits a low‑privileged attacker with network access to HTTP to compromise the application. Successful exploitation can lead to complete takeover of the system, resulting in loss of confidentiality, integrity, and availability of data. The weakness is a form of unauthorized access that allows an attacker to bypass authentication controls.
Affected Systems
Oracle Corporation: Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 are affected.
Risk and Exploitability
The CVSS 3.1 base score is 7.5, indicating substantial impact. EPSS score is less than 1 %, suggesting low current exploitation probability, but the vulnerability is not listed in CISA KEV. Although the attack vector is indirect (network via HTTP), the attacker only needs low privileges and no user interaction, which makes the threat realistic against exposed installations. Mitigation remains critical because a successful attack gives the attacker full control.
OpenCVE Enrichment