Impact
Oracle Essbase software is vulnerable to an easily exploitable flaw that permits an unauthenticated attacker to gain complete control of the system. Owing to its HTTP interface, the attacker may send crafted requests that bypass security checks, resulting in a full takeover with loss of confidentiality, integrity, and availability. The CVSS calculation reflects high severity, with no authentication required and direct network access as the required vector.
Affected Systems
The flaw affects Oracle Essbase version 21.8.1.0.0. This is the only supported version identified in the advisory. No other versions or equivalent products are listed as affected.
Risk and Exploitability
With a CVSS base score of 9.8, the vulnerability is critical. The EPSS score is <1%, indicating a very low probability of exploitation. The lack of a KEV listing suggests no known exploitation campaigns yet. The description indicates it is easily exploitable over HTTP, so an attacker only needs network access and no credentials.
OpenCVE Enrichment