QID 376182
Date Published: 2021-12-20
QID 376182: Oracle Essbase Administration Services Security Update (cpuoct2021)
Oracle Hyperion Essbase Administration Services (Essbase Administration Services) software is a robust, cross-platform graphical user interface that makes Essbase administration tasks easy to perform.
Vulnerability allows unauthenticated attacker with network access via HTTP to compromise Essbase Administration Services.
Affected Versions:
Essbase Administration Services prior to 11.1.2.4.046
NOTE:
Flagged as potential as only able to check high level version
QID Detection Logic (Authenticated):
Windows: Fetch high level version of Essbase Administration Services from the registry.
Successful exploitation of these vulnerabilities may allow an remoter attacker to compromise Essbase Administration Services console.
Solution
The vendor has released these fixes. More information refer vendor advisory cpuoct2021.
Vendor References
CVEs related to QID 376182
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cpuoct2021 |
|