Skip to content

CVE-2023-22010 | Hyperion Essbase

Vulnerability in Oracle Essbase (component: Security and Provisioning). The supported version that is affected is 21.4.3.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Essbase. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Essbase accessible data. CVSS 3.1 Base Score 2.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N)..This CVE has a CVSS3.1 score of 2.2 and a Base Severity of LOW.

InfoDetails
CVE IDCVE-2023-22010
CVE StatePUBLISHED
BaseScore2.2
BaseSeverityLOW
VectorStringCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
VersionNA

References for CVE-2023-22010 :
https://www.oracle.com/security-alerts/cpujul2023.html

Metric TypeMetric Score
AttackVector(AV)NETWORK
AttackComplexity(AC)HIGH
PrivilegesRequired(PR)HIGH
UserInteraction(UI)NONE
Scope(S)UNCHANGED
Confidentiality(C)LOW
Availability(A)NONE
Integrity(I)NONE