Executive brief
Oracle BI Publisher is a component of Oracle Analytics that generates and distributes business reports. A low-privileged attacker with network access can exploit a vulnerability in the SOAP service to gain unauthorized access to critical business data, including the ability to create, modify, or delete reports and data across the platform. This could expose sensitive analytics and business intelligence to unauthorized users or lead to data manipulation.
Technical details
The vulnerability is in the BI Platform Security component of Oracle BI Publisher and allows a low-privileged attacker to perform unauthorized actions via SOAP protocol without requiring additional user interaction. The attack requires network access and low-level privileges but enables high-impact unauthorized modification and deletion of critical data, as well as unauthorized read access to sensitive information. While the vulnerability resides in BI Publisher, successful exploitation can impact additional Oracle products due to a scope change. Fixes are available in supported versions; affected versions include 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0.
Affected products
- Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Timeline
- 2026-09-15: disclosed