Record summary

CVE-2019-2861 has a selected CVSS score of 4.2 (medium); EIP currently links 1 catalogued exploit.

Description

Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Planning. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Planning accessible data. CVSS 3.0 Base Score 4.2 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N).

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 1, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List11.1.2.4affected

Proofs of concept

1

Catalogued exploits

ExploitDBOracle Hyperion Planning 11.1.2.3 - XML External EntityExploitDB exploitby Lucas DinucciNot analyzed1 file
ExploitDB

PoC details

References

3