Executive brief
Oracle Business Intelligence Enterprise Edition is a widely-deployed analytics platform used by enterprises to create reports and dashboards. A critical vulnerability in its Platform Security component allows an attacker with low-level network access to completely compromise the system and potentially attack other connected applications. A successful exploit could lead to unauthorized access to sensitive business data, system takeover, and operational disruption.
Technical details
The vulnerability is an easily exploitable flaw in the Platform Security component of Oracle Business Intelligence Enterprise Edition version 12.2.1.4.0. It allows an attacker with low privileges and network access via HTTP to escalate privileges and gain full control of the system. The vulnerability has cross-system impact (scope change), meaning successful exploitation could be used as a stepping stone to compromise other products on the network. Patches are expected as part of Oracle's security update cycle, though immediate patching or mitigation of version 12.2.1.4.0 is strongly recommended.
Affected products
- Oracle Business Intelligence Enterprise Edition 12.2.1.4.0
Timeline
- 2026-09-15: disclosed
- other: Oracle security advisory published; exploit status unknown at time of advisory