Impact
The flaw exists in the Administration component of Oracle BI Publisher. A low‑privilege attacker who can reach the application over HTTP can exploit the vulnerability, but the attack must involve a separate person interacting with the system. Successful exploitation gives the attacker unauthorized read access to all data that the application exposes and, depending on configuration, the ability to update, insert, or delete data. This results in high confidentiality impact and low integrity impact, while availability is not directly affected.
Affected Systems
Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 are affected according to vendor documentation.
Risk and Exploitability
The CVSS 3.1 base score of 7.6 marks this vulnerability as high severity. The EPSS score of less than 1% indicates exploitation is unlikely but not impossible. The flaw is not listed in the CISA KEV catalog. Because the vector shows a scope change (S:C), a successful attack could lift privileges within the BI Publisher instance, giving the attacker broader access to data than normally permitted. Although the current attack requires another person’s interaction, the presence of a scope change suggests a potentially larger impact if the attack chain is fully realized.
OpenCVE Enrichment