Oracle Hyperion Financial Reporting vulnerabilities
13 known vulnerabilities affecting oracle/hyperion_financial_reporting.
Total CVEs
13
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH3MEDIUM7LOW1
Vulnerabilities
Page 1 of 1
CVE-2025-50108MEDIUMCVSS 5.4v11.2.20.0.0002025-07-15
CVE-2025-50108 [MEDIUM] CWE-284 CVE-2025-50108: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Work
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Workspace). The supported version that is affected is 11.2.20.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interacti
nvd
CVE-2021-35665MEDIUMCVSS 6.1v11.2.6.02021-10-20
CVE-2021-35665 [MEDIUM] CVE-2021-35665: Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Repository)
Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that is affected is 11.2.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Financial Reporting. Successful attacks require human interaction from a person other th
nvd
CVE-2021-27807MEDIUMCVSS 5.5v11.1.2.4v11.2.6.02021-03-19
CVE-2021-27807 [MEDIUM] CWE-834 CVE-2021-27807: A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects
A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
nvd
CVE-2021-27906MEDIUMCVSS 5.5v11.1.2.4v11.2.6.02021-03-19
CVE-2021-27906 [MEDIUM] CWE-789 CVE-2021-27906: A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
nvd
CVE-2019-17566HIGHCVSS 7.5v11.1.2.4v11.2.5.02020-11-12
CVE-2019-17566 [HIGH] CWE-918 CVE-2019-17566: Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by th
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
nvd
CVE-2020-11023MEDIUMCVSS 6.1KEVPoCv11.1.2.42020-04-29
CVE-2020-11023 [MEDIUM] CWE-79 CVE-2020-11023: In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option>
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
nvd
CVE-2020-2769LOWCVSS 2.4v11.1.2.42020-04-15
CVE-2020-2769 [LOW] CVE-2020-2769: Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Web Based R
Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Web Based Report Designer). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Financial Reporting. Successful attacks require human interaction from a perso
nvd
CVE-2019-2959MEDIUMCVSS 4.2v11.1.2.42019-10-16
CVE-2019-2959 [MEDIUM] CVE-2019-2959: Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Security Mo
Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Security Models). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Financial Reporting. Successful attacks require human interaction from a person oth
nvd
CVE-2019-0228CRITICALCVSS 9.8v11.1.2.4v11.2.6.02019-04-17
CVE-2019-0228 [CRITICAL] CWE-611 CVE-2019-0228: Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent att
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
nvd
CVE-2018-2907HIGHCVSS 8.6v11.1.22018-07-18
CVE-2018-2907 [HIGH] CVE-2018-2907: Vulnerability in the Hyperion Financial Reporting component of Oracle Hyperion (subcomponent: Securi
Vulnerability in the Hyperion Financial Reporting component of Oracle Hyperion (subcomponent: Security Models). The supported version that is affected is 11.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Financial Reporting. While the vulnerability is in Hyperion Financial Reporting, att
nvd
CVE-2017-10310HIGHCVSS 7.5v11.1.22017-10-19
CVE-2017-10310 [HIGH] CWE-200 CVE-2017-10310: Vulnerability in the Oracle Hyperion Financial Reporting component of Oracle Hyperion (subcomponent:
Vulnerability in the Oracle Hyperion Financial Reporting component of Oracle Hyperion (subcomponent: Security Models). The supported version that is affected is 11.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerabilit
nvd
CVE-2017-10358MEDIUMCVSS 6.4v11.1.22017-10-19
CVE-2017-10358 [MEDIUM] CVE-2017-10358: Vulnerability in the Oracle Hyperion Financial Reporting component of Oracle Hyperion (subcomponent:
Vulnerability in the Oracle Hyperion Financial Reporting component of Oracle Hyperion (subcomponent: Workspace). The supported version that is affected is 11.1.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. While the vulnerability is in Oracle Hyperion Financ
nvd
CVE-2016-3493CRITICALCVSS 9.8v11.1.2.42016-07-21
CVE-2016-3493 [CRITICAL] CVE-2016-3493: Unspecified vulnerability in the Hyperion Financial Reporting component in Oracle Hyperion 11.1.2.4
Unspecified vulnerability in the Hyperion Financial Reporting component in Oracle Hyperion 11.1.2.4 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Security Models.
nvd