Unauthorized Access Flaw in Oracle Essbase Administration Services
CVE-2021-35653
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 20 October 2021
What is CVE-2021-35653?
A vulnerability exists in Oracle Essbase Administration Services allowing low-privileged attackers with network access via HTTP to compromise the service. The flaw impacts versions prior to 11.1.2.4.046 and 21.3, potentially leading to unauthorized access to sensitive data. While the vulnerability is primarily in the EAS Console, it poses risks to additional integrated products, enabling attackers to exploit this weakness to gain critical information or full access to data managed by Essbase Administration Services.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Hyperion Essbase Administration Services < 11.1.2.4.046
Hyperion Essbase Administration Services < 21.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved