ZeroHour

CVE-2026-83319

moderate

Authenticated Data Exposure via SOAP Web Service in Oracle BI Publisher 12.2.1.4.0

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

Oracle BI Publisher 12.2.1.4.0 contains an easily exploitable flaw in its Web Service API (SOAP) that allows a low-privileged attacker with network access to compromise the application. Successful attacks can result in unauthorized access to critical data or complete access to all data reachable through Oracle BI Publisher, and because the vulnerability has a scope change (S:C), the impact can extend to additional products beyond BI Publisher itself. Exploitation requires valid low-privileged credentials and a path to the SOAP endpoint, but needs no user interaction and has low attack complexity, yielding a CVSS 3.1 base score of 7.7 (confidentiality-only impact). Organizations running the affected version of Oracle BI Publisher, typically as part of Oracle Fusion Middleware or Oracle Analytics deployments, are at risk of broad report and business-data disclosure. No public proof of concept is known and the flaw is not listed in CISA's KEV catalog, so there is no indication of active exploitation at this time.

What to do: Apply the Oracle Critical Patch Update that remediates this flaw to all Oracle BI Publisher 12.2.1.4.0 installations. Restrict network access to BI Publisher SOAP web service endpoints to trusted sources, and review which low-privileged accounts can reach them. Audit recent access logs for anomalous data retrieval by low-privilege SOAP accounts and rotate credentials for service accounts that interface with the Web Service API.

Affected
Oracle BI Publisher (Oracle Analytics, component: Web Service API)12.2.1.4.0
Estimated exposure
moderate≈1,000–10,000 internet-reachable BI Publisher servers, plus a larger unknown population of intranet deployments — BI Publisher ships with Oracle Fusion Middleware/Analytics in enterprise deployments, and public internet scans of Oracle middleware endpoints (e.g., xmlpserver services) historically surface only low-thousands of exposed instances since…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.