CVE-2025-21532

Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Install). Supported versions that are affected are Prior to 8.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Analytics Desktop executes to compromise Oracle Analytics Desktop. Successful attacks of this vulnerability can result in takeover of Oracle Analytics Desktop. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVSS

No CVSS.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:oracle:analytics_desktop:*:*:*:*:*:*:*:*

History

02 Jul 2025, 16:33

Type Values Removed Values Added
References () https://www.oracle.com/security-alerts/cpujan2025.html - () https://www.oracle.com/security-alerts/cpujan2025.html - Vendor Advisory
CPE cpe:2.3:a:oracle:analytics_desktop:*:*:*:*:*:*:*:*
First Time Oracle
Oracle analytics Desktop

22 Jan 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : unknown

21 Jan 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-21 21:15

Updated : 2025-07-02 16:33


NVD link : CVE-2025-21532

Mitre link : CVE-2025-21532


JSON object : View

Products Affected

oracle

  • analytics_desktop
CWE

No CWE.