CVE-2026-83319
moderateAuthenticated Data Exposure via SOAP Web Service in Oracle BI Publisher 12.2.1.4.0
Oracle BI Publisher 12.2.1.4.0 contains an easily exploitable flaw in its Web Service API (SOAP) that allows a low-privileged attacker with network access to compromise the application. Successful attacks can result in unauthorized access to critical data or complete access to all data reachable through Oracle BI Publisher, and because the vulnerability has a scope change (S:C), the impact can extend to additional products beyond BI Publisher itself. Exploitation requires valid low-privileged credentials and a path to the SOAP endpoint, but needs no user interaction and has low attack complexity, yielding a CVSS 3.1 base score of 7.7 (confidentiality-only impact). Organizations running the affected version of Oracle BI Publisher, typically as part of Oracle Fusion Middleware or Oracle Analytics deployments, are at risk of broad report and business-data disclosure. No public proof of concept is known and the flaw is not listed in CISA's KEV catalog, so there is no indication of active exploitation at this time.
What to do: Apply the Oracle Critical Patch Update that remediates this flaw to all Oracle BI Publisher 12.2.1.4.0 installations. Restrict network access to BI Publisher SOAP web service endpoints to trusted sources, and review which low-privileged accounts can reach them. Audit recent access logs for anomalous data retrieval by low-privilege SOAP accounts and rotate credentials for service accounts that interface with the Web Service API.
| Oracle BI Publisher (Oracle Analytics, component: Web Service API) | 12.2.1.4.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.