---
id: CVE-2025-53049
title: >-
  Vulnerability in the Oracle Business Intelligence Enterprise Edition product
  of Oracle Analytics (component: Analytics Web Administration)
summary: >-
  Vulnerability in the Oracle Business Intelligence Enterprise Edition product
  of Oracle Analytics (component: Analytics Web Administration).  Supported
  versions that are affected are 7.6.0.0.0 and  8.2.0.0.0. Easily exploitable
  vulnerabil…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-284
vendor: oracle
product: business_intelligence
affected:
  - business_intelligence = 7.6.0.0.0
  - business_intelligence = 8.2.0.0.0
published: '2025-10-21'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-53049'
references:
  - url: 'https://www.oracle.com/security-alerts/cpuoct2025.html'
    label: secalert_us@oracle.com
tags:
  - nvd
epss: 0.00357
epssPercentile: 0.27332
ingestedAt: '2026-10-08T11:31:27.462Z'
---

## Overview

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Administration).  Supported versions that are affected are 7.6.0.0.0 and  8.2.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H).

## Affected

- `business_intelligence = 7.6.0.0.0`
- `business_intelligence = 8.2.0.0.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
