Impact
The flaw is an insufficient privilege management issue (CWE-269) that allows a low‑privileged network user to abuse the BI server’s HTTP interface. Successful exploitation results in full takeover of the Oracle Business Intelligence Enterprise Edition, granting an attacker complete control over the platform and enabling loss of confidentiality, integrity, and availability of all BI data and services.
Affected Systems
Oracle Business Intelligence Enterprise Edition is affected in versions 8.2.0.0.0 and 26.01.0.0.0. Attackers can reach the vulnerable component via the standard HTTP interface exposed on the network.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 signals high severity, while the EPSS score of less than 1% indicates a low but nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote over HTTP and does not require user interaction; only low privileges are necessary on the BI server to successfully compromise it.
OpenCVE Enrichment