Oracle BI Advisory Spans Legacy and Current Releases

Oracle and NCSC-NL updated an advisory on Aug. 19 covering multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition and Oracle BI Publisher. The affected versions include 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0, so this is not limited to one current branch. NCSC-NL says low-privilege users with network access over HTTP or SOAP can reach flaws in BI Search and BI Publisher web-service interfaces that may expose sensitive data, bypass authentication, escalate privileges, alter or delete reports and data, and in some cases take over the system. Some bugs can also cause denial of service. The practical concern is mixed estates: if older Oracle BI branches still exist alongside current ones, they sit in the same advisory scope. For shops that use BI as a reporting front end to more valuable data, a flaw here can become a wider access problem than the product name suggests.

Part of the PlainSec briefing for 2026-08-19

Every edition of this story: Oracle BI Advisory Spans Legacy and Current Releases

Sources