cbcvebase.

Oracle Hyperion Bi vulnerabilities

12 known vulnerabilities affecting oracle/hyperion_bi.

Total CVEs
12
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH1MEDIUM8LOW3

Vulnerabilities

Page 1 of 1
CVE-2021-45105P1MEDIUMCVSS 5.9ExploitedPoCRansomwarefixed in 11.2.8.02021-12-18
CVE-2021-45105 [MEDIUM] CWE-20 CVE-2021-45105: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from u Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
nvd
CVE-2017-10312P3HIGHCVSS 7.1v11.1.2.42017-10-19
CVE-2017-10312 [HIGH] CVE-2017-10312: Vulnerability in the Oracle Hyperion BI+ component of Oracle Hyperion (subcomponent: UI and Visualiz Vulnerability in the Oracle Hyperion BI+ component of Oracle Hyperion (subcomponent: UI and Visualization). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion BI+. Successful attacks require human interaction from a person other than th
nvd
CVE-2017-10359P4MEDIUMCVSS 5.4v11.1.2.4.02017-10-19
CVE-2017-10359 [MEDIUM] CVE-2017-10359: Vulnerability in the Oracle Hyperion BI+ component of Oracle Hyperion (subcomponent: UI and Visualiz Vulnerability in the Oracle Hyperion BI+ component of Oracle Hyperion (subcomponent: UI and Visualization). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion BI+. Successful attacks require human interaction from a person other than
nvd
CVE-2021-2439P4MEDIUMCVSS 4.3v11.1.2.4v11.2.5.02021-07-21
CVE-2021-2439 [MEDIUM] CVE-2021-2439: Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization). Supported versions that are affected are 11.1.2.4 and 11.2.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion BI+. Successful attacks require human interaction from a person other
nvd
CVE-2019-2415P4MEDIUMCVSS 4.3v11.1.2.42019-01-16
CVE-2019-2415 [MEDIUM] CVE-2019-2415: Vulnerability in the Hyperion BI+ component of Oracle Hyperion (subcomponent: Foundation UI & Servle Vulnerability in the Hyperion BI+ component of Oracle Hyperion (subcomponent: Foundation UI & Servlets). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion BI+. Successful attacks require human interaction from a person other than the attacker
nvd
CVE-2020-14767P4MEDIUMCVSS 4.2v11.1.2.42020-10-21
CVE-2020-14767 [MEDIUM] CVE-2020-14767: Vulnerability in the Hyperion BI+ product of Oracle Hyperion (component: IQR-Foundation service). Th Vulnerability in the Hyperion BI+ product of Oracle Hyperion (component: IQR-Foundation service). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise Hyperion BI+. Successful attacks require human interaction from a person other than t
nvd
CVE-2020-14560P4MEDIUMCVSS 4.2v11.1.2.42020-07-15
CVE-2020-14560 [MEDIUM] CVE-2020-14560: Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion BI+. Successful attacks require human interaction from a person other than the
nvd
CVE-2018-2595P4MEDIUMCVSS 4.3v11.1.2.42018-01-18
CVE-2018-2595 [MEDIUM] CVE-2018-2595: Vulnerability in the Hyperion BI+ component of Oracle Hyperion (subcomponent: Foundation UI & Servle Vulnerability in the Hyperion BI+ component of Oracle Hyperion (subcomponent: Foundation UI & Servlets). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion BI+. Successful attacks require human interaction from a person other than the attacker
nvd
CVE-2018-2594P4MEDIUMCVSS 4.3v11.1.2.42018-01-18
CVE-2018-2594 [MEDIUM] CVE-2018-2594: Vulnerability in the Hyperion BI+ component of Oracle Hyperion (subcomponent: Foundation UI & Servle Vulnerability in the Hyperion BI+ component of Oracle Hyperion (subcomponent: Foundation UI & Servlets). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion BI+. Successful attacks require human interaction from a person other than the attacker
nvd
CVE-2024-21257P4LOWCVSS 3.0v11.2.18.0.0002024-10-15
CVE-2024-21257 [LOW] CVE-2024-21257: Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.2.18.0.000. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion BI+ executes to compromise Oracle Hyp
nvd
CVE-2018-3184P4LOWCVSS 2.4v11.1.2.42018-10-17
CVE-2018-3184 [LOW] CVE-2018-3184: Vulnerability in the Hyperion BI+ component of Oracle Hyperion (subcomponent: IQR - Foundation Servi Vulnerability in the Hyperion BI+ component of Oracle Hyperion (subcomponent: IQR - Foundation Services). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion BI+. Successful attacks require human interaction from a person other than the attacker.
nvd
CVE-2020-14770P4LOWCVSS 2.0v11.1.2.42020-10-21
CVE-2020-14770 [LOW] CVE-2020-14770: Vulnerability in the Hyperion BI+ product of Oracle Hyperion (component: IQR-Foundation service). Th Vulnerability in the Hyperion BI+ product of Oracle Hyperion (component: IQR-Foundation service). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise Hyperion BI+. Successful attacks require human interaction from a person other than the
nvd
Oracle Hyperion Bi vulnerabilities | cvebase