Impact
A flaw in the Platform Security component of Oracle Business Intelligence Enterprise Edition allows a malicious actor who already possesses high‑privileged network credentials to gain full control of the affected BI instance. The vulnerability is triggered over ordinary HTTP traffic and, once exploited, it can compromise confidentiality, integrity, and availability of all business data housed in the instance. The weakness fits categories of bad authorization and privilege escalation, exposing the system to remote takeover when the conditions are met.
Affected Systems
Oracle Corporation’s Oracle Business Intelligence Enterprise Edition is affected in versions 8.2.0.0.0 and 26.01.0.0.0. The product is part of Oracle Analytics, and the vulnerability manifests through the HTTP interface of the BI platform.
Risk and Exploitability
The CVSS v3.1 base score of 7.2 indicates moderate to high severity. The EPSS score of less than 1% suggests the vulnerability has not yet been widely exploited, and it is not listed in the CISA KEV catalog. Because the flaw requires high‑privileged credentials and can be reached from the network, the potential impact is a full takeover of the BI instance if an attacker can inject malicious traffic over HTTP. The risk remains significant for any environment that exposes the BI platform to external access without prior high‑level authentication.
OpenCVE Enrichment