Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujan2026.html |
|
Thu, 22 Jan 2026 06:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 21 Jan 2026 07:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). The supported version that is affected is 25.04.07. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Planning and Budgeting Cloud Service executes to compromise Oracle Planning and Budgeting Cloud Service. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Planning and Budgeting Cloud Service accessible data. Note: Update EPM Agent. Please refer to <a href="https://docs.oracle.com/en/cloud/saas/enterprise-performance-management-common/diepm/epm_agent_downloading_agent_110x80569d70.html">Downloading the EPM Agent for more information. CVSS 3.1 Base Score 4.2 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N). | |
| First Time appeared |
Oracle
Oracle planning And Budgeting Cloud Service |
|
| CPEs | cpe:2.3:a:oracle:planning_and_budgeting_cloud_service:25.04.07:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle planning And Budgeting Cloud Service |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-01-21T20:48:53.795Z
Reserved: 2026-01-05T18:07:34.708Z
Link: CVE-2026-21922
Updated: 2026-01-21T20:48:50.661Z
Status : Received
Published: 2026-01-20T22:15:54.500
Modified: 2026-01-20T22:15:54.500
Link: CVE-2026-21922
No data.
OpenCVE Enrichment
No data.
No weakness.