First published: Tue Jan 21 2025(Updated: )
Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Install). Supported versions that are affected are Prior to 8.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Analytics Desktop executes to compromise Oracle Analytics Desktop. Successful attacks of this vulnerability can result in takeover of Oracle Analytics Desktop. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Analytics | <8.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-21532 is classified as an easily exploitable vulnerability affecting Oracle Analytics Desktop versions prior to 8.1.0.
To remediate CVE-2025-21532, update Oracle Analytics Desktop to version 8.1.0 or later.
Any user or organization using Oracle Analytics Desktop versions prior to 8.1.0 is affected by CVE-2025-21532.
CVE-2025-21532 is an easily exploitable vulnerability that allows a low privileged attacker to compromise Oracle Analytics Desktop.
CVE-2025-21532 affects the Install component of the Oracle Analytics Desktop product.