Unauthorized Read Access Vulnerability in Oracle Essbase Administration Services
CVE-2021-35655

5.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
20 October 2021

Summary

A vulnerability exists in Oracle Essbase Administration Services (EAS Console) that allows an unauthenticated attacker with network access via HTTP to exploit the system. This vulnerability affects EAS versions prior to 11.1.2.4.046 and prior to 21.3, enabling unauthorized users to gain read access to sensitive data within the system. Proper security measures must be implemented to mitigate the risk associated with this vulnerability. For further details, refer to Oracle's security alerts.

Affected Version(s)

Hyperion Essbase Administration Services < 11.1.2.4.046

Hyperion Essbase Administration Services < 21.3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.