vendor:
Hyperion Enterprise Performance Management System
by:
Lucas Dinucci
4.2
CVSS
MEDIUM
XML External Entity (XXE) Injection
611
CWE
Product Name: Hyperion Enterprise Performance Management System
Affected Version From: 11.1.2.3
Affected Version To: 11.1.2.3
Patch Exists: YES
Related CWE: CVE-2019-2861
CPE: oracle:hyperion_enterprise_performance_management_system
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
XXE Injection Oracle Hyperion
An authenticated attacker could exploit this vulnerability to disclose internal files using the file URI handler, internal file shares, internal port scanning, remote code execution and denial of service attacks.
Mitigation:
Apply the patch provided by the vendor.