Oracle Essbase Administration Services vulnerabilities
7 known vulnerabilities affecting oracle/essbase_administration_services.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH3MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2021-35683CRITICALCVSS 9.9fixed in 11.1.2.4.0472022-01-19
CVE-2021-35683 [CRITICAL] CVE-2021-35683: Vulnerability in the Oracle Essbase Administration Services product of Oracle Essbase (component: EA
Vulnerability in the Oracle Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported version that is affected is Prior to 11.1.2.4.047. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Essbase Administration Services. While the vulnerability is in Ora
nvd
CVE-2021-35652CRITICALCVSS 10.0fixed in 11.1.2.4.046≥ 21.0, < 21.32021-10-20
CVE-2021-35652 [CRITICAL] CVE-2021-35652: Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Conso
Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported versions that are affected are Prior to 11.1.2.4.046 and Prior to 21.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Essbase Administration Services. While the vulnerability i
nvd
CVE-2021-35653HIGHCVSS 7.7fixed in 11.1.2.4.046≥ 21.0, < 21.32021-10-20
CVE-2021-35653 [HIGH] CVE-2021-35653: Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Conso
Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported versions that are affected are Prior to 11.1.2.4.046 and Prior to 21.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Essbase Administration Services. While the vulnerability is in
nvd
CVE-2021-35654HIGHCVSS 7.5fixed in 11.1.2.4.046≥ 21.0, < 21.32021-10-20
CVE-2021-35654 [HIGH] CVE-2021-35654: Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Conso
Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported versions that are affected are Prior to 11.1.2.4.046 and Prior to 21.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Essbase Administration Services. Successful attacks of this vu
nvd
CVE-2021-35651HIGHCVSS 8.5fixed in 11.1.2.4.046≥ 21.0, < 21.32021-10-20
CVE-2021-35651 [HIGH] CVE-2021-35651: Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Conso
Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported versions that are affected are Prior to 11.1.2.4.046 and Prior to 21.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Essbase Administration Services. While the vulnerability is in
nvd
CVE-2021-35655MEDIUMCVSS 5.3fixed in 11.1.2.4.046≥ 21.0, < 21.32021-10-20
CVE-2021-35655 [MEDIUM] CVE-2021-35655: Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Conso
Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported versions that are affected are Prior to 11.1.2.4.046 and Prior to 21.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Essbase Administration Services. Successful attacks of this
nvd
CVE-2019-10219MEDIUMCVSS 6.1fixed in 11.1.2.4.47v11.1.2.4.472019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd