CVE-2021-35653 is an easily exploitable vulnerability affecting Oracle Essbase Administration Services (EAS Console) versions prior to 11.1.2.4.046 and 21.3. A low-privileged attacker with network access via HTTP can compromise EAS, potentially leading to unauthorized access to critical data or complete access to all EAS-accessible data, with a CVSS 3.1 Base Score of 7.7 (High). While the vulnerability is in EAS, successful attacks can significantly impact additional products. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in the CISA KEV catalog, indicating no active exploitation. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.1.2.4.046CPE match | cpe:2.3:a:oracle:hyperion_essbase_administration_services:*:*:*:*:*:*:*:* | ||
< 21.3CPE match | cpe:2.3:a:oracle:hyperion_essbase_administration_services:*:*:*:*:*:*:*:* | ||
< 11.1.2.4.046CPE matchmatch criteria | cpe:2.3:a:oracle:essbase_administration_services:*:*:*:*:*:*:*:* | ||
>= 21.0, < 21.3CPE matchmatch criteria | cpe:2.3:a:oracle:essbase_administration_services:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.