Security Vulnerability in Oracle Essbase by Oracle
CVE-2023-21943
5.3MEDIUM
Summary
A security vulnerability exists in Oracle Essbase that allows an unauthenticated attacker with network access via HTTP to compromise the system. The affected version is 21.4. Exploiting this vulnerability necessitates human interaction from a user other than the attacker, which poses a significant risk of unauthorized access to sensitive data or even complete access to all data available within Oracle Essbase. Organizations using this version should address this issue promptly to mitigate the potential for data breaches.
Affected Version(s)
Hyperion Essbase 21.4
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved