Executive brief
Oracle BI Publisher is a reporting and analytics component of Oracle Analytics used to create and distribute business intelligence reports. This vulnerability allows a low-privileged attacker to trick users into compromising the system, potentially exposing sensitive business data or allowing unauthorized modifications to reports and data accessed through BI Publisher.
Technical details
The vulnerability is a cross-site scripting (XSS) issue in the Administration component of Oracle BI Publisher, exploitable over HTTP with low-level privileges and requires user interaction (social engineering or clickjacking). The attack has a network vector with low complexity. Successful exploitation allows attackers to gain unauthorized access to critical data or perform unauthorized insert, update, or delete operations on BI Publisher data. The scope is marked as changed, indicating potential impact to additional Oracle Analytics products. The vulnerability affects versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0.
Affected products
- Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Timeline
- 2026-09-15: disclosed