Executive brief
Oracle BI Publisher is a reporting and analytics tool used to create and distribute business intelligence reports across enterprises. A vulnerability in its security component allows a low-privileged network attacker to gain unauthorized access to sensitive business data and reports, or disrupt service availability. The impact extends beyond BI Publisher itself to other connected Oracle Analytics products.
Technical details
This vulnerability in the BI Publisher Security component is easily exploitable via HTTP by a low-privileged authenticated attacker on the network. The vulnerability allows circumvention of authorization controls, enabling unauthorized access to critical data and complete exposure of BI Publisher-accessible information, as well as partial denial of service. The CVSS 3.1 score of 8.5 reflects high confidentiality and low availability impact with scope change, indicating cross-system compromise risk. Patch availability and specific technical remediation details are not yet publicly available from the provided advisory text.
Affected products
- Oracle BI Publisher 12.2.1.4.0
Timeline
- 2026-09-15: disclosed