CVE-2018-3140 is a vulnerability in the Hyperion Essbase Administration Services (EAS Console) component of Oracle Hyperion, specifically affecting version 11.1.2.4. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise the service. The vulnerability has a CVSS 3.0 Base Score of 6.1 (Medium), indicating potential unauthorized modification or limited unauthorized read access to data. Successful attacks require user interaction and may impact additional products beyond Hyperion Essbase Administration Services. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.1.2.4CPE matchmatch criteria | cpe:2.3:a:oracle:hyperion:11.1.2.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.