CVE-2021-2433

Vulnerability in the Essbase Analytic Provider Services product of Oracle Essbase (component: Web Services). Supported versions that are affected are 11.1.2.4 and 21.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Essbase Analytic Provider Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Essbase Analytic Provider Services. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:essbase_analytic_provider_services:11.1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:essbase_analytic_provider_services:21.2:*:*:*:*:*:*:*

History

21 Nov 2024, 06:03

Type Values Removed Values Added
References () https://www.oracle.com/security-alerts/cpujul2021.html - Vendor Advisory () https://www.oracle.com/security-alerts/cpujul2021.html - Vendor Advisory

26 Jul 2021, 19:11

Type Values Removed Values Added
References (MISC) https://www.oracle.com/security-alerts/cpujul2021.html - (MISC) https://www.oracle.com/security-alerts/cpujul2021.html - Vendor Advisory
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:oracle:essbase_analytic_provider_services:11.1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:essbase_analytic_provider_services:21.2:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5

21 Jul 2021, 15:21

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-21 15:16

Updated : 2024-11-21 06:03


NVD link : CVE-2021-2433

Mitre link : CVE-2021-2433

CVE.ORG link : CVE-2021-2433


JSON object : View

Products Affected

oracle

  • essbase_analytic_provider_services