Impact
A flaw in the Analytics Server component of Oracle's Business Intelligence Enterprise Edition allows a low‑privileged attacker who can log onto the underlying host to compromise the BI server. The flaw permits an attacker to take full control of the BI instance, leading to loss of confidential data, integrity tampering, and availability disruption. The vulnerability is identified by CWE-269, indicating improper privilege management.
Affected Systems
Oracle BI Enterprise Edition (Oracle Analytics) for versions 8.2.0.0.0 and 26.01.0.0.0 are impacted. These are the only versions listed as affected in the vulnerability advisory.
Risk and Exploitability
The CVSS 3.1 base score of 7.8 marks this vulnerability as high severity. However, the EPSS score of less than 1% indicates that, as of the last assessment, exploitation attempts are very rare. The vulnerability is not yet recorded in CISA's KEV catalogue. Successful exploitation requires the attacker to be able to log onto the host that runs the Analytics Server, indicating a local‑adversary attack with low privilege. Consequently, the risk to an environment with restricted access to the host is substantial if the host is compromised, but the likelihood of activity is currently low.
OpenCVE Enrichment