{
  "cve": "CVE-2026-83299",
  "enrichment": {
    "created": "2026-09-16T22:45:09.217041+00:00",
    "title": "Unauthenticated HTTP Exploit Allows Oracle Business Intelligence Enterprise Edition Takeover",
    "updated": "2026-09-20T08:15:16.578876+00:00",
    "vendors": []
  },
  "epss": {
    "score": 0.00348
  },
  "mitre": {
    "cpes": [
      "cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*"
    ],
    "created": "2026-09-15T20:04:51.832000+00:00",
    "description": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General).   The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 8.1,
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2026/83xxx/CVE-2026-83299.json",
    "references": [
      "https://www.oracle.com/security-alerts/cspusep2026.html"
    ],
    "title": null,
    "updated": "2026-09-17T13:10:37.235000+00:00",
    "vendors": [
      "oracle",
      "oracle$PRODUCT$business_intelligence"
    ],
    "weaknesses": []
  },
  "nvd": {
    "cpes": [],
    "created": "2026-09-15T20:18:42.763000+00:00",
    "description": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General).   The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 8.1,
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2026/CVE-2026-83299.json",
    "references": [
      "https://www.oracle.com/security-alerts/cspusep2026.html"
    ],
    "title": null,
    "updated": "2026-09-17T14:17:40.477000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-269"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-09-15T20:15:00+00:00",
        "data": [
          {
            "details": {
              "new": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General).   The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
              "old": null
            },
            "type": "description"
          },
          {
            "details": [
              "oracle",
              "oracle$PRODUCT$business_intelligence"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "oracle",
                "oracle$PRODUCT$business_intelligence"
              ],
              "removed": []
            },
            "type": "vendors"
          },
          {
            "details": {
              "added": [
                "https://www.oracle.com/security-alerts/cspusep2026.html"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 8.1,
                  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "47baad29-1b6c-4212-b086-8d06aa86cdd4"
      },
      {
        "created": "2026-09-16T23:00:00+00:00",
        "data": [
          {
            "details": {
              "new": "Unauthenticated Remote Code Execution in Oracle Business Intelligence Enterprise Edition",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-94"
              ],
              "removed": []
            },
            "type": "weaknesses"
          }
        ],
        "id": "8da408a8-5eac-4ad2-a949-a6f23df00a81"
      },
      {
        "created": "2026-09-17T14:30:00+00:00",
        "data": [
          {
            "details": {
              "added": [
                "CWE-269"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "no",
                    "Exploitation": "none",
                    "Technical Impact": "total"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "98ceb21e-6567-4f7c-83d0-4cee194d2285"
      },
      {
        "created": "2026-09-18T16:00:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "Unauthenticated Remote Code Execution in Oracle Business Intelligence Enterprise Edition"
            },
            "type": "title"
          },
          {
            "details": {
              "added": [],
              "removed": [
                "CWE-94"
              ]
            },
            "type": "weaknesses"
          }
        ],
        "id": "07b48905-2f48-4aff-9a6a-1e249d60a7d8"
      },
      {
        "created": "2026-09-20T08:30:00+00:00",
        "data": [
          {
            "details": {
              "new": "Unauthenticated HTTP Exploit Allows Oracle Business Intelligence Enterprise Edition Takeover",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "04e4659d-1f42-4f99-a9f1-815f0b60ffb9"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*"
      ],
      "providers": [
        "mitre"
      ]
    },
    "created": {
      "data": "2026-09-15T20:04:51.832000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General).   The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 8.1,
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.00348
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "no",
            "Exploitation": "none",
            "Technical Impact": "total"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://www.oracle.com/security-alerts/cspusep2026.html"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": "Unauthenticated HTTP Exploit Allows Oracle Business Intelligence Enterprise Edition Takeover",
      "provider": "enrichment"
    },
    "updated": {
      "data": "2026-09-20T08:15:16.578876+00:00",
      "provider": "enrichment"
    },
    "vendors": {
      "data": [
        "oracle",
        "oracle$PRODUCT$business_intelligence"
      ],
      "providers": [
        "mitre"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-269"
      ],
      "providers": [
        "nvd",
        "vulnrichment"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2026-09-15T20:04:51.832000+00:00",
    "description": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General).   The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "no",
          "Exploitation": "none",
          "Technical Impact": "total"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": null,
    "updated": "2026-09-17T13:00:13.339000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2026/83xxx/CVE-2026-83299.json",
    "weaknesses": [
      "CWE-269"
    ]
  }
}