Vulnerability in Oracle Hyperion Planning Affects Application Development Framework
CVE-2020-14764

4.2MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
21 October 2020

Summary

A vulnerability in Oracle's Hyperion Planning software, particularly within the Application Development Framework, allows an attacker with high privileges and network access through HTTP to exploit the system. Exploitation requires user interaction from an individual not associated with the attacker. Successful exploitation could lead to unauthorized creation, deletion, or modification of critical data, compromising the integrity of all data accessible through Hyperion Planning. This poses serious risks to data security and integrity management.

Affected Version(s)

Hyperion Planning 11.1.2.4

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.