Unauthorized Access Flaw in Oracle Essbase Administration Services
CVE-2021-35653

7.7HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
20 October 2021

Summary

A vulnerability exists in Oracle Essbase Administration Services allowing low-privileged attackers with network access via HTTP to compromise the service. The flaw impacts versions prior to 11.1.2.4.046 and 21.3, potentially leading to unauthorized access to sensitive data. While the vulnerability is primarily in the EAS Console, it poses risks to additional integrated products, enabling attackers to exploit this weakness to gain critical information or full access to data managed by Essbase Administration Services.

Affected Version(s)

Hyperion Essbase Administration Services < 11.1.2.4.046

Hyperion Essbase Administration Services < 21.3

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.