Impact
The platform security component of Oracle Business Intelligence Enterprise Edition contains a CWE‑269 access‑control flaw that allows a high‑privileged attacker with network connectivity over HTTP to gain full control of the application, potentially compromising confidentiality, integrity, and availability of all BI services.
Affected Systems
Oracle Business Intelligence Enterprise Edition versions 8.2.0.0.0 and 26.01.0.0.0, both supported by Oracle, are affected. The servers are exposed over HTTP on the network.
Risk and Exploitability
The CVSS base score of 7.2 indicates a medium‑high severity; the EPSS score of < 1% suggests a low likelihood of exploitation, but the vulnerability requires only high‑privileged credentials and an HTTP request, making it feasible for attackers who have breached the network or have valid accounts. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment