漏洞标题
N/A
漏洞描述信息
Oracle Hyperion中的Hyperion Essbase Administration Services组件(子组件:EAS Console)的漏洞。受影响的支持版本是11.1.2.4。容易利用的漏洞允许通过HTTP网络访问的无验证攻击者 compromising Hyperion Essbase Administration Services。成功的攻击需要攻击者之外的人进行手动交互,虽然漏洞存在于Hyperion Essbase Administration Services,但攻击可能严重影响其他产品。利用此漏洞的成功攻击可能导致未经授权的更新、插入或删除访问Hyperion Essbase Administration Services可访问数据的部分,以及未经授权的读取访问Hyperion Essbase Administration Services可访问数据的部分。CVSS 3.0基础得分6.1(保密性和完整性影响)。CVSS向量:(CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
Vulnerability in the Hyperion Essbase Administration Services component of Oracle Hyperion (subcomponent: EAS Console). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Essbase Administration Services. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Hyperion Essbase Administration Services, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Hyperion Essbase Administration Services accessible data as well as unauthorized read access to a subset of Hyperion Essbase Administration Services accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
Oracle Hyperion Essbase Administration Services组件安全漏洞
漏洞描述信息
Oracle Hyperion是美国甲骨文(Oracle)公司的一套财务建模应用软件。Hyperion Essbase Administration Services是其中的一个用于管理Essbase数据库的组件,它提供了一个跨平台的图形用户界面,可同时查看和编辑多个Hyperion Essbase数据库、应用程序、脚本以及其他对象的属性。 Oracle Hyperion中的Hyperion Essbase Administration Services组件11.1.2.4版本的EAS Console子组
CVSS信息
N/A
漏洞类别
授权问题