Executive brief
Oracle Business Intelligence Enterprise Edition (part of Oracle Analytics) is used to search, analyze, and report on business data across enterprises. A vulnerability in the BI Search component allows an authenticated attacker with low privileges to modify, delete, or access sensitive data, as well as disrupt service availability. This could lead to unauthorized exposure of confidential business intelligence, data manipulation, and temporary service outages.
Technical details
The vulnerability is an authorization flaw in the BI Search component of Oracle Business Intelligence Enterprise Edition version 12.2.1.4.0. It is easily exploitable via HTTP by a low-privileged authenticated attacker without user interaction. The flaw allows an attacker to gain unauthorized access to create, modify, or delete critical data, read sensitive information, and trigger partial denial-of-service conditions. Exploitation requires network access and valid authentication credentials, but does not require administrative privileges or complex attack preconditions.
Affected products
- Oracle Business Intelligence Enterprise Edition 12.2.1.4.0
Timeline
- 2026-09-15: disclosed