Oracle Hyperion Financial Reporting vulnerabilities
42 known vulnerabilities affecting oracle/hyperion_financial_reporting.
Total CVEs
42
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH10MEDIUM23LOW3
Vulnerabilities
Page 1 of 3
CVE-2020-11023P1MEDIUMCVSS 6.1KEVPoCv11.1.2.42020-04-29
CVE-2020-11023 [MEDIUM] CWE-79 CVE-2020-11023: In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option>
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
nvd
CVE-2026-70745P2CRITICALCVSS 9.8v11.2.25.0.0002026-08-18
CVE-2026-70745 [CRITICAL] CWE-284 CVE-2026-70745: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability c
nvd
CVE-2026-70740P2CRITICALCVSS 9.8v11.2.25.0.0002026-08-18
CVE-2026-70740 [CRITICAL] CWE-284 CVE-2026-70740: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability c
nvd
CVE-2026-70739P2CRITICALCVSS 9.8v11.2.25.0.0002026-08-18
CVE-2026-70739 [CRITICAL] CWE-284 CVE-2026-70739: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability c
nvd
CVE-2026-70741P2CRITICALCVSS 9.1v11.2.25.0.0002026-08-18
CVE-2026-70741 [CRITICAL] CWE-284 CVE-2026-70741: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability ca
nvd
CVE-2026-70742P2HIGHCVSS 8.8v11.2.25.0.0002026-08-18
CVE-2026-70742 [HIGH] CWE-284 CVE-2026-70742: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can r
nvd
CVE-2026-70787P2HIGHCVSS 8.8v11.2.25.0.0002026-08-18
CVE-2026-70787 [HIGH] CWE-284 CVE-2026-70787: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can re
nvd
CVE-2019-17566P3HIGHCVSS 7.5v11.1.2.4v11.2.5.02020-11-12
CVE-2019-17566 [HIGH] CWE-918 CVE-2019-17566: Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by th
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
nvd
CVE-2016-3493P3CRITICALCVSS 9.8v11.1.2.42016-07-21
CVE-2016-3493 [CRITICAL] CVE-2016-3493: Unspecified vulnerability in the Hyperion Financial Reporting component in Oracle Hyperion 11.1.2.4
Unspecified vulnerability in the Hyperion Financial Reporting component in Oracle Hyperion 11.1.2.4 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Security Models.
nvd
CVE-2019-0228P3CRITICALCVSS 9.8v11.1.2.4v11.2.6.02019-04-17
CVE-2019-0228 [CRITICAL] CWE-611 CVE-2019-0228: Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent att
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
nvd
CVE-2026-70744P3HIGHCVSS 8.1v11.2.25.0.0002026-08-18
CVE-2026-70744 [HIGH] CWE-284 CVE-2026-70744: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can
nvd
CVE-2026-70749P3HIGHCVSS 8.1v11.2.25.0.0002026-08-18
CVE-2026-70749 [HIGH] CWE-284 CVE-2026-70749: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can
nvd
CVE-2026-70752P3HIGHCVSS 7.5v11.2.25.0.0002026-08-18
CVE-2026-70752 [HIGH] CWE-284 CVE-2026-70752: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can r
nvd
CVE-2018-2907P3HIGHCVSS 8.6v11.1.22018-07-18
CVE-2018-2907 [HIGH] CVE-2018-2907: Vulnerability in the Hyperion Financial Reporting component of Oracle Hyperion (subcomponent: Securi
Vulnerability in the Hyperion Financial Reporting component of Oracle Hyperion (subcomponent: Security Models). The supported version that is affected is 11.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Financial Reporting. While the vulnerability is in Hyperion Financial Reporting, att
nvd
CVE-2026-70746P3HIGHCVSS 8.1v11.2.25.0.0002026-08-18
CVE-2026-70746 [HIGH] CWE-284 CVE-2026-70746: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction f
nvd
CVE-2017-10310P3HIGHCVSS 7.5v11.1.22017-10-19
CVE-2017-10310 [HIGH] CWE-200 CVE-2017-10310: Vulnerability in the Oracle Hyperion Financial Reporting component of Oracle Hyperion (subcomponent:
Vulnerability in the Oracle Hyperion Financial Reporting component of Oracle Hyperion (subcomponent: Security Models). The supported version that is affected is 11.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerabilit
nvd
CVE-2026-70750P3HIGHCVSS 7.8v11.2.25.0.0002026-08-18
CVE-2026-70750 [HIGH] CWE-284 CVE-2026-70750: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Reporting executes to compromise Oracle Hyperion Financial Rep
nvd
CVE-2026-70769P3MEDIUMCVSS 6.5v11.2.25.0.0002026-08-18
CVE-2026-70769 [MEDIUM] CWE-284 CVE-2026-70769: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability c
nvd
CVE-2026-70767P3MEDIUMCVSS 6.5v11.2.25.0.0002026-08-18
CVE-2026-70767 [MEDIUM] CWE-284 CVE-2026-70767: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can
nvd
CVE-2026-70751P3MEDIUMCVSS 6.8v11.2.25.0.0002026-08-18
CVE-2026-70751 [MEDIUM] CWE-284 CVE-2026-70751: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interacti
nvd
1 / 3Next →