CVE-2018-2907Corporation Hyperion Financial Reporting vulnerability

3 documents3 sources
Severity
8.6HIGHNVD
EPSS
1.7%
top 17.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 18
Latest updateMay 13

Description

Vulnerability in the Hyperion Financial Reporting component of Oracle Hyperion (subcomponent: Security Models). The supported version that is affected is 11.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Financial Reporting. While the vulnerability is in Hyperion Financial Reporting, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:NExploitability: 3.9 | Impact: 4.0

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5mrq-xgcw-w84j: Vulnerability in the Hyperion Financial Reporting component of Oracle Hyperion (subcomponent: Security Models)2022-05-13
CVEList
CVE-2018-2907: Vulnerability in the Hyperion Financial Reporting component of Oracle Hyperion (subcomponent: Security Models)2018-07-18
CVE-2018-2907 — HIGH severity | cvebase