Platform Security Vulnerability in Oracle Business Intelligence Enterprise Edition
CVE-2025-30759

6.1MEDIUM

What is CVE-2025-30759?

A vulnerability exists in Oracle Business Intelligence Enterprise Edition's Platform Security component, which allows unauthenticated attackers with network access via HTTP to compromise sensitive data. While direct attacks target Oracle Business Intelligence, they may also affect other integrated products. Successful exploitation of this vulnerability can lead to unauthorized access, enabling attackers to perform actions such as updating, inserting, or deleting accessible data. Additionally, attackers may gain unauthorized read access to a subset of data within the affected systems. It requires human interaction from someone other than the attacker, making it essential for users to be aware of potential threats.

Affected Version(s)

Oracle Business Intelligence Enterprise Edition 7.6.0.0.0

Oracle Business Intelligence Enterprise Edition 8.2.0.0.0

Oracle Business Intelligence Enterprise Edition 12.2.1.4.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.