My Oracle Support Banner

Compliances of Older Libcurl.so.X libraries (Doc ID 3051051.1)

Last updated on OCTOBER 07, 2024

Applies to:

Hyperion Essbase - Version 21.5.3.0.0 and later
Hyperion BI+ - Version 11.2.15.0.000 and later
Information in this document applies to any platform.

Goal

Tenable Nessus scanner has identified files in the environment that are out of compliance. Specifically, the scanner identified older versions of the libcurl.so.4 file in multiple locations. The customer wanted to know if the issue was patched in 11.2.18.

Cause:

The cause of the issue is a known vulnerability, CVE-2023-38545, which affects the libcurl.so.4 files in the Essbase client environment. The customer's installed versions are outdated, leading to this vulnerability.

Solution

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Goal
Solution
References


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.