Unauthenticated Access Vulnerability in Hyperion Common Events by Oracle
CVE-2018-3175

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 October 2018

Summary

The Hyperion Common Events component of Oracle Hyperion has a vulnerability that could be exploited by an unauthenticated attacker having network access via HTTP. While the vulnerability primarily exists in the Hyperion Common Events, exploitation can lead to unauthorized update, insert, or delete actions on accessible data, as well as unauthorized reading of a subset of this data. Successful exploitation necessitates human interaction from a non-attacker party, thereby increasing the complexity of exploitation. The potential impact on additional interconnected products raises concerns regarding broader data integrity and confidentiality.

Affected Version(s)

Hyperion Common Events 11.1.2.4

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.