Impact
Oracle Essbase software is vulnerable to an easily exploitable flaw that permits an unauthenticated attacker to gain complete control of the system. Owing to its HTTP interface, the attacker may send crafted requests that bypass security checks, resulting in a full takeover with loss of confidentiality, integrity, and availability. The CVSS calculation reflects high severity, with no authentication required and direct network access as the required vector.
Affected Systems
The flaw affects Oracle Essbase version 21.8.1.0.0. This is the only supported version identified in the advisory. No other versions or equivalent products are listed as affected.
Risk and Exploitability
With a CVSS base score of 9.8, severity is critical. The EPSS score is not supplied, so the exact probability of exploitation in the wild is unknown, but the lack of a KEV listing indicates it has not yet been observed in known exploit campaigns. The description explicitly states that the vulnerability is easily exploitable through network access via HTTP, implying that an attacker requires only generic network connectivity to the affected instance and no privileged credentials to succeed.
OpenCVE Enrichment