ZeroHour

CVE-2026-83302

moderate

Authenticated Data Exposure in Oracle BI Publisher 12.2.1.4.0

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

Oracle BI Publisher 12.2.1.4.0 (part of Oracle Analytics, BI Publisher Security component) contains an easily exploitable flaw reachable over HTTP by an attacker holding only low-privileged credentials. Successful exploitation yields unauthorized access to critical data — or complete access to all data reachable through Oracle BI Publisher — plus the ability to cause a partial denial of service. Because the vulnerability carries a scope change (CVSS 3.1 8.5, AV:N/AC:L/PR:L/S:C/C:H/A:L), successful attacks may also significantly impact products beyond BI Publisher itself. Any organization running the affected 12.2.1.4.0 release, particularly instances reachable on a network by low-privilege or internal users, is affected. No public proof of concept is known and the flaw is not on the CISA KEV catalog, so exploitation status is none known as of this writing.

What to do: Apply the Oracle Critical Patch Update that remediates this flaw to all BI Publisher 12.2.1.4.0 instances and any bundled deployments (e.g., OBIEE/Fusion Middleware) as soon as the patch is available. Restrict HTTP access to BI Publisher so only trusted networks, VPN, or SSO-fronted users can reach it, and audit low-privilege accounts for anomalous report/data access or unexpected service disruption.

Affected
Oracle BI Publisher (Oracle Analytics, component: BI Publisher Security)12.2.1.4.0
Estimated exposure
moderate≈1,000–5,000 internet-exposed BI Publisher servers, plus a larger unknown population of internal-only enterprise deployments — BI Publisher ships with Oracle Fusion Middleware/OBIEE and is typically deployed inside large enterprises; public internet-wide scans historically show only low-thousands of exposed OBIEE/BI Publisher login endpoints, while most instances…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Publisher Security). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.