Impact
A flaw in the Web Service API of Oracle BI Publisher allows a low‑privileged attacker who can reach the SOAP endpoint over the network to gain unauthorized access to highly confidential data. The vulnerability’s CVSS vector shows high confidentiality impact while only low system privileges are required, indicating that the attacker can obtain complete data access.
Affected Systems
Oracle BI Publisher version 12.2.1.4.0, a component of Oracle Analytics.
Risk and Exploitability
The CVSS base score of 7.7 combined with an EPSS value below 1% indicates that the vulnerability is exploitable yet the current likelihood of widespread exploitation is low. Because the flaw lies in access control, a simple SOAP request from an attacker who can reach the service will expose all data that the service can deliver, potentially affecting ancillary Oracle Analytics products. The vulnerability is not yet listed in CISA’s KEV catalog, but the potential for cross‑product impact warrants prompt attention.
OpenCVE Enrichment