Impact
The Platform Security component of Oracle Business Intelligence Enterprise Edition contains a flaw that lets a low‑privileged user who is logged into the underlying infrastructure gain control of the BI platform. An attacker can obtain full takeover, exposing, altering or deleting confidential data and disrupting service availability. The weakness is represented by CWE-269 and carries a CVSS 3.1 base score of 7.5, indicating severe confidentiality, integrity and availability impacts.
Affected Systems
Oracle Business Intelligence Enterprise Edition version 26.01.0.0.0 deployed on the organization’s infrastructure is vulnerable. The flaw is not limited to the BI platform; the scope change means that other applications running on the same host could also be compromised once the BI platform is taken over.
Risk and Exploitability
The CVSS vector AV:L/AC:H/PR:L/UI:R/S:C indicates that exploitation requires local access, high attack complexity, low attacker privileges, and user interaction from a third party, making automated attacks difficult. The EPSS score is below 1 %, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation has not been observed. However, when successfully exploited the attacker can achieve complete system takeover, posing a severe risk for environments that run the affected version of Oracle BI.
OpenCVE Enrichment