CVE-2019-2861 is a vulnerability in the Oracle Hyperion Planning component (specifically, the Security subcomponent) of Oracle Hyperion, affecting version 11.1.2.4. This medium-severity vulnerability (CVSS 4.2) allows a highly privileged attacker with network access via HTTP to compromise data integrity within Hyperion Planning. Exploitation is difficult, requiring human interaction from a non-attacker, but can lead to unauthorized creation, deletion, or modification of critical data. While no active exploitation is confirmed and community discussion is minimal, an ExploitDB entry (EDB-47196) exists, indicating potential for XML External Entity (XXE) attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.1.2.4CPE matchmatch criteria | cpe:2.3:a:oracle:hyperion_planning:11.1.2.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.