PT-2025-42984 · Oracle · Oracle Essbase+1

Published

2025-10-21

·

Updated

2025-10-21

·

CVE-2025-61763

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Oracle Essbase version 21.7.3.0.0
Description An issue exists in Oracle Essbase, specifically within the Essbase Web Platform component. A low-privileged attacker with network access via HTTP can compromise the system. Successful exploitation may lead to unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to all Oracle Essbase accessible data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-61763

Affected Products

Essbase Web Platform
Oracle Essbase