Security and Provisioning Vulnerability in Oracle Essbase Software
CVE-2022-21508

5.8MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 July 2022

Summary

A security vulnerability exists in Oracle Essbase's Security and Provisioning component, affecting version 21.3. This flaw allows a high-privileged attacker with valid logon access to exploit the system, enabling unauthorized actions such as the creation, deletion, or modification of critical data. Furthermore, successful exploitation of this vulnerability requires human interaction from an individual other than the attacker. As a result, it poses a significant risk of unauthorized access to sensitive data and could compromise the integrity of all accessible data in Oracle Essbase.

Affected Version(s)

Hyperion Essbase 21.3

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.