Executive brief
Oracle BI Publisher is a reporting and analytics component of Oracle Analytics that allows users to access and create business intelligence reports. A low-privileged attacker with network access can exploit a vulnerability in the Web Server to gain unauthorized access to sensitive data or modify database contents across the platform. This vulnerability has a scope change impact, meaning successful attacks can compromise other connected Oracle systems beyond BI Publisher itself.
Technical details
The vulnerability is a privilege escalation issue in the Oracle BI Publisher Web Server component, exploitable by a low-privileged attacker over the network via HTTP (no user interaction required). The attack does not require special access controls to be bypassed (low complexity), allowing remote compromise with only basic authentication. An attacker can achieve unauthorized read access to critical confidential data and selective write/delete/update access to BI Publisher data. The scope is marked as changed, indicating lateral impact to other Oracle products. Patches are expected to be available through Oracle's security updates for affected versions (8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0).
Affected products
- Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Timeline
- 2026-09-15: disclosed