Vulnerability in Oracle Hyperion Essbase Administration Services
CVE-2023-21961

6MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 July 2023

Summary

A vulnerability exists in the Oracle Hyperion Essbase Administration Services, specifically within the EAS Administration and EAS Console components. An attacker with privileged credentials can exploit this vulnerability to gain unauthorized access to sensitive data within the Oracle Hyperion environment. This exploitation can potentially lead to a significant compromise of various products integrated with the Oracle Hyperion system, as the effects of the breach may extend beyond the compromised service. Organizations using the affected version, 21.4.3.0.0, should prioritize patching and enhancing their security posture to mitigate risks associated with unauthorized data access.

Affected Version(s)

Hyperion Essbase Administration Services 21.4.3.0.0

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.