Unauthorized Access Vulnerability in Oracle Hyperion Workspace by Oracle
CVE-2023-22060
7.6HIGH
Summary
An access control vulnerability exists in Oracle Hyperion Workspace that allows a low-privileged attacker to exploit the system via HTTP. This vulnerability may lead to unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to sensitive information. Additionally, this flaw can allow attackers to cause a partial denial of service, affecting the availability of the workspace. Successful exploitation requires user interaction, making it a potential threat in environments where users are unaware of the risks.
Affected Version(s)
Hyperion BI+ 11.2.13.0.000
References
CVSS V3.1
Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved