Vulnerability in Oracle Hyperion and Essbase Analytic Provider Services
CVE-2021-2244

10CRITICAL

Key Information:

Vendor
Oracle
Vendor
CVE Published:
22 April 2021

Summary

A vulnerability exists in Oracle's Hyperion Analytic Provider Services and Essbase Analytic Provider Services, specifically in the JAPI component. This weakness permits an unauthenticated attacker with network access to take control of the affected services. Exploitation of this vulnerability requires human interaction from an external user and may have wider implications for other connected Oracle products. Given its nature, successful exploitation can lead to significant unauthorized access, affecting confidentiality, integrity, and availability of the services.

Affected Version(s)

Hyperion Analytic Provider Services 11.1.2.4

Hyperion Analytic Provider Services 12.2.1.4

Hyperion Analytic Provider Services 21.2

References

EPSS Score

7% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.