Unauthenticated Access Vulnerability in Oracle Hyperion Essbase Administration Services
CVE-2021-2349

8.6HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
20 July 2021

Summary

A critical vulnerability exists in the Oracle Hyperion Essbase Administration Services, specifically within the EAS Console component. This weakness allows an unauthenticated attacker with network access via HTTP to exploit the system. While the vulnerability specifically impacts Hyperion Essbase Administration Services, successful exploitation could lead to unauthorized access to sensitive data, compromising the integrity of the entire service. Affected versions include 11.1.2.4 and 21.2, highlighting the urgency for users to assess their exposure and implement protective measures as soon as possible.

Affected Version(s)

Hyperion Essbase Administration Services 11.1.2.4

Hyperion Essbase Administration Services 21.2

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.