CVE-2013-3803 is an unspecified vulnerability in Oracle Hyperion BI+ versions 11.1.1.3, 11.1.1.4.107 and earlier, 11.1.2.1.129 and earlier, and 11.1.2.2.305 and earlier. This vulnerability allows remote authenticated users to compromise confidentiality through unknown vectors related to the Intelligence Service. With a CVSS score of 3.5, it has a network attack vector, medium attack complexity, and requires authentication, leading to a partial confidentiality impact. While not actively exploited in the wild and not on the KEV catalog, a public exploit for directory traversal exists on ExploitDB, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.1.1.4, <= 11.1.1.4.107CPE matchmatch criteria | cpe:2.3:a:oracle:hyperion:*:*:*:*:*:*:*:* | ||
>= 11.1.2.1, <= 11.1.2.1.129CPE matchmatch criteria | cpe:2.3:a:oracle:hyperion:*:*:*:*:*:*:*:* | ||
>= 11.1.2.2, <= 11.1.2.2.305CPE matchmatch criteria | cpe:2.3:a:oracle:hyperion:*:*:*:*:*:*:*:* | ||
11.1.1.3CPE matchmatch criteria | cpe:2.3:a:oracle:hyperion:11.1.1.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.