Vulnerability in Hyperion Analytic Provider Services by Oracle
CVE-2020-14768

4.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
21 October 2020

Summary

The vulnerability present in Oracle's Hyperion Analytic Provider Services enables low privileged attackers with physical access to potentially compromise the service. Exploitation necessitates human interaction from a third party, allowing for unauthorized updates, inserts, and deletions of data, as well as unauthorized read access. Attackers may also be able to inflict partial denial of service (partial DoS) on the service. Mitigation is essential to protect against potential data breaches and service disruptions.

Affected Version(s)

Hyperion Analytic Provider Services 11.1.2.4

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.