Executive brief
Oracle Business Intelligence Enterprise Edition is a reporting and analytics platform used by enterprises to analyze and visualize business data. A low-privilege attacker with network access can exploit a vulnerability in the Presentation Services component to gain unauthorized access to sensitive business intelligence data. This vulnerability could expose critical analytics data and compromise the confidentiality of information across the organization.
Technical details
A network-reachable vulnerability exists in Oracle Business Intelligence Enterprise Edition's Presentation Services component, exploitable via SOAP protocol by authenticated (low-privileged) attackers. The vulnerability allows unauthorized access to critical data within the system and potentially affects additional products due to scope change. The attack requires network access and valid authentication credentials but no additional user interaction. Successful exploitation results in high-impact confidentiality breach without modification or availability impact. Patches are expected from Oracle's security advisory for affected versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0.
Affected products
- Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Timeline
- 2026-09-15: disclosed