Impact
The flaw is a low‑privilege remote access issue in the Analytics Actions component of Oracle Business Intelligence Enterprise Edition. An attacker who can reach the HTTP interface may bypass access controls and read or modify sensitive data exposed by the platform, compromising confidentiality and some integrity of the protected information. The weakness allows unauthorized insertion, update, or deletion of data that the BI platform makes available, potentially affecting all data accessible through the BI system. The issue involves improper access control (CWE-284).
Affected Systems
Vulnerable versions are 8.2.0.0.0 and 26.01.0.0.0 of Oracle Business Intelligence Enterprise Edition. The issue resides in the Analytics Actions component and may extend to other Oracle Analytics products because the vulnerability can change scope.
Risk and Exploitability
The CVSS v3.1 base score of 8.5 denotes high severity. The EPSS score is below 1 %, indicating a low current probability of exploitation, and the flaw is not listed in CISA’s KEV catalog. Attackers require only network reachability via HTTP and low privileges; no user interaction or elevated rights are needed. Given the potential scope change, an exploit could expose all data accessible through the BI platform.
OpenCVE Enrichment