CVE-2024-21257
published 2024-10-15CVE-2024-21257: Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.2.18.0.000…
PriorityP49low3CVSS 3.1
AVAACLPRLUIRSUCLINAN
EPSS
0.35%
26.8th percentile
Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.2.18.0.000. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion BI+ executes to compromise Oracle Hyperion BI+. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion BI+ accessible data. CVSS 3.1 Base Score 3.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | hyperion_bi | — | — |
| oracle_corporation | oracle_hyperion_bi | — | — |
CVSS provenance
nvdv3.13.0LOWCVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
vendor_oracle3.0LOW
vendor_redhat3.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v3cc-4rr8-r8xv: Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization)
ghsa_unreviewed·2024-10-15
CVE-2024-21257 [LOW] GHSA-v3cc-4rr8-r8xv: Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization)
Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.2.18.0.000. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion BI+ executes to compromise Oracle Hyperion BI+. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion BI+ accessible data. CVSS 3.1 Base Score 3.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N).
GHSA
XWiki has no right protection on rollback action
ghsa·2024-01-08
CVE-2024-21648 [HIGH] CWE-274 XWiki has no right protection on rollback action
XWiki has no right protection on rollback action
### Impact
The rollback action is missing a right protection: it means that a user can rollback to a previous version of the page to gain rights they don't have anymore.
This vulnerability impacts all version of XWiki since rollback action is available.
### Patches
The problem has been patched in XWiki 14.10.16, 15.5.3 and 15.8-rc-1 by ensuring that the rights are checked before performing the rollback.
### Workarounds
There's no workaround for this vulnerability, except paying attention to delete old versions of documents that could allow users to gain more rights.
### References
* JIRA ticket: https://jira.xwiki.org/browse/XWIKI-21257
* Commit: [4de72875ca49602796165412741033bfdbf1e680](https://github.com/xwiki/xwiki-platform/commi
Red Hat
UI and Visualization: From CVEorg collector
vendor_redhat·2024-10-15·CVSS 3.0
CVE-2024-21257 [LOW] UI and Visualization: From CVEorg collector
UI and Visualization: From CVEorg collector
Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.2.18.0.000. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion BI+ executes to compromise Oracle Hyperion BI+. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion BI+ accessible data. CVSS 3.1 Base Score 3.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N).
Oracle
Oracle Oracle Hyperion Risk Matrix: UI and Visualization — CVE-2024-21257
vendor_oracle·2024-10-15·CVSS 3.0
CVE-2024-21257 [LOW] Oracle Oracle Hyperion Risk Matrix: UI and Visualization — CVE-2024-21257
Oracle Oracle Hyperion Risk Matrix: UI and Visualization vulnerability
CVE: CVE-2024-21257
CVSS: 3.0
Protocol: HTTP
Remote exploit: No
Affected versions: Adjacent
Network
Advisory: cpuoct2024 (OCT 2024)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-15
Published