Oracle Hyperion vulnerabilities

23 known vulnerabilities affecting oracle/hyperion.

Total CVEs
23
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM16LOW5

Vulnerabilities

Page 1 of 2
CVE-2023-22062HIGHCVSS 8.5v11.2.13.0.0002023-07-18
CVE-2023-22062 [HIGH] CVE-2023-22062: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Repo Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that is affected is 11.2.13.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. While the vulnerability is in Oracle Hyperion Finan
nvd
CVE-2018-3142HIGHCVSS 7.7v11.1.2.42018-10-17
CVE-2018-3142 [HIGH] CVE-2018-3142: Vulnerability in the Hyperion Essbase Administration Services component of Oracle Hyperion (subcompo Vulnerability in the Hyperion Essbase Administration Services component of Oracle Hyperion (subcomponent: EAS Console). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Hyperion Essbase Administration Services. While the vulnerability is in Hyperion Ess
nvd
CVE-2018-3140MEDIUMCVSS 6.1v11.1.2.42018-10-17
CVE-2018-3140 [MEDIUM] CVE-2018-3140: Vulnerability in the Hyperion Essbase Administration Services component of Oracle Hyperion (subcompo Vulnerability in the Hyperion Essbase Administration Services component of Oracle Hyperion (subcomponent: EAS Console). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Essbase Administration Services. Successful attacks require human intera
nvd
CVE-2018-3141MEDIUMCVSS 5.8v11.1.2.42018-10-17
CVE-2018-3141 [MEDIUM] CVE-2018-3141: Vulnerability in the Hyperion Essbase Administration Services component of Oracle Hyperion (subcompo Vulnerability in the Hyperion Essbase Administration Services component of Oracle Hyperion (subcomponent: EAS Console). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Essbase Administration Services. While the vulnerability is in Hyperion
nvd
CVE-2015-4823LOWCVSS 1.2v11.1.2.32015-10-21
CVE-2015-4823 [LOW] CVE-2015-4823: Unspecified vulnerability in the Hyperion Installation Technology component in Oracle Hyperion 11.1. Unspecified vulnerability in the Hyperion Installation Technology component in Oracle Hyperion 11.1.2.3 allows local users to affect confidentiality via unknown vectors related to Essbase Rapid Deploy.
nvd
CVE-2015-2584MEDIUMCVSS 4.0v11.1.2.2v11.1.2.32015-07-16
CVE-2015-2584 [MEDIUM] CVE-2015-2584: Unspecified vulnerability in the Hyperion Enterprise Performance Management Architect component in O Unspecified vulnerability in the Hyperion Enterprise Performance Management Architect component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect integrity via unknown vectors related to Security, a different vulnerability than CVE-2015-2592.
nvd
CVE-2015-4773MEDIUMCVSS 4.0v11.1.2.2v11.1.2.3+1 more2015-07-16
CVE-2015-4773 [MEDIUM] CVE-2015-4773: Unspecified vulnerability in the Hyperion Common Security component in Oracle Hyperion 11.1.2.2, 11. Unspecified vulnerability in the Hyperion Common Security component in Oracle Hyperion 11.1.2.2, 11.1.2.3, and 11.1.2.4 allows remote authenticated users to affect availability via unknown vectors related to User Account Update.
nvd
CVE-2015-2592LOWCVSS 3.5v11.1.2.2v11.1.2.32015-07-16
CVE-2015-2592 [LOW] CVE-2015-2592: Unspecified vulnerability in the Hyperion Enterprise Performance Management Architect component in O Unspecified vulnerability in the Hyperion Enterprise Performance Management Architect component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect integrity via unknown vectors related to Security, a different vulnerability than CVE-2015-2584.
nvd
CVE-2015-0509MEDIUMCVSS 4.3v11.1.2.2v11.1.2.32015-04-16
CVE-2015-0509 [MEDIUM] CVE-2015-0509: Unspecified vulnerability in the Oracle Hyperion BI+ component in Oracle Hyperion 11.1.2.2 and 11.1. Unspecified vulnerability in the Oracle Hyperion BI+ component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect integrity via unknown vectors related to Reporting and Analysis.
nvd
CVE-2014-3707MEDIUMCVSS 4.3v11.1.2.2v11.1.2.32014-11-15
CVE-2014-3707 [MEDIUM] CWE-200 CVE-2014-3707: The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COP The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to read sensitive memory information.
nvd
CVE-2014-0436MEDIUMCVSS 4.3v11.1.2.2v11.1.2.32014-07-17
CVE-2014-0436 [MEDIUM] CVE-2014-0436: Unspecified vulnerability in the Hyperion BI+ component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 all Unspecified vulnerability in the Hyperion BI+ component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect integrity via unknown vectors related to Web Analysis.
nvd
CVE-2014-4271MEDIUMCVSS 5.0v11.1.2.2v11.1.2.32014-07-17
CVE-2014-4271 [MEDIUM] CVE-2014-4271: Unspecified vulnerability in the Hyperion Essbase component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 Unspecified vulnerability in the Hyperion Essbase component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect availability via unknown vectors related to Agent.
nvd
CVE-2014-4270MEDIUMCVSS 4.0v11.1.2.2v11.1.2.32014-07-17
CVE-2014-4270 [MEDIUM] CVE-2014-4270: Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11. Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality via unknown vectors related to User Interface, a different vulnerability than CVE-2014-4269.
nvd
CVE-2014-4203MEDIUMCVSS 4.1v11.1.2.2v11.1.2.32014-07-17
CVE-2014-4203 [MEDIUM] CVE-2014-4203: Unspecified vulnerability in the Hyperion Enterprise Performance Management Architect component in O Unspecified vulnerability in the Hyperion Enterprise Performance Management Architect component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Property Editing.
nvd
CVE-2014-4269MEDIUMCVSS 4.0v11.1.2.2v11.1.2.32014-07-17
CVE-2014-4269 [MEDIUM] CVE-2014-4269: Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11. Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality via unknown vectors related to User Interface, a different vulnerability than CVE-2014-4270.
nvd
CVE-2014-4246LOWCVSS 3.5v11.1.2.2v11.1.2.32014-07-17
CVE-2014-4246 [LOW] CVE-2014-4246: Unspecified vulnerability in the Hyperion Analytic Provider Services component in Oracle Hyperion 11 Unspecified vulnerability in the Hyperion Analytic Provider Services component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality via vectors related to SVP.
nvd
CVE-2014-4206LOWCVSS 3.3v11.1.2.2v11.1.2.32014-07-17
CVE-2014-4206 [LOW] CVE-2014-4206: Unspecified vulnerability in the Hyperion Enterprise Performance Management Architect component in O Unspecified vulnerability in the Hyperion Enterprise Performance Management Architect component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows local users to affect integrity and availability via unknown vectors related to Data Synchronizer.
nvd
CVE-2014-2454MEDIUMCVSS 4.3v11.1.2.2v11.1.2.32014-04-16
CVE-2014-2454 [MEDIUM] CVE-2014-2454: Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11. Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect confidentiality via unknown vectors related to User Interface.
nvd
CVE-2014-2455MEDIUMCVSS 6.0v11.1.2.2v11.1.2.32014-04-16
CVE-2014-2455 [MEDIUM] CVE-2014-2455: Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11. Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to User Interface.
nvd
CVE-2014-2453MEDIUMCVSS 4.3v11.1.2.2v11.1.2.32014-04-16
CVE-2014-2453 [MEDIUM] CVE-2014-2453: Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11. Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect integrity via unknown vectors related to User Interface.
nvd