Security Vulnerability in Oracle Essbase by Oracle
CVE-2023-21942

5.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 April 2023

Summary

A vulnerability exists in Oracle Essbase that allows an unauthenticated attacker with network access via HTTP to potentially compromise the system. Exploitation of this vulnerability necessitates human interaction from an individual other than the attacker, hence complicating the attack scenario. Successful exploitation can lead to unauthorized access to sensitive data, enabling an attacker to gain access to all Oracle Essbase accessible data. Organizations utilizing Oracle Essbase 21.4 must be mindful of this security issue to protect their data integrity.

Affected Version(s)

Hyperion Essbase 21.4

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.