Impact
A vulnerability exists in the Calculator component of Oracle Essbase 21.8.1.0.0 that allows an attacker with low privileges and network access via HTTP to exploit the system. Successful use of the flaw can lead to full takeover of the Essbase instance, resulting in loss of confidentiality, integrity, and availability. The CVSS 3.1 base score of 8.8 highlights a high‑severity threat with an attack vector of network, low attack complexity, low privilege required, no user interaction, and common impact to all systems.
Affected Systems
This issue affects Oracle Corporation’s Essbase product, specifically version 21.8.1.0.0. No other versions or products are listed as impacted.
Risk and Exploitability
With an AV:N vector and low privilege requirements, an adversary can readily launch an attack from any network connection to the HTTP interface. The absence of a mitigation in the CISA KEV catalog does not diminish the potential danger, as the CVSS score indicates a high likelihood of major damage. While no EPSS data is available, the straightforward nature of the exploitation path suggests that the vulnerability could be leveraged by malicious actors once the product is detected in a networked environment.
OpenCVE Enrichment