Oracle Hyperion Financial Reporting vulnerabilities
42 known vulnerabilities affecting oracle/hyperion_financial_reporting.
Total CVEs
42
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH10MEDIUM23LOW3
Vulnerabilities
Page 2 of 3
CVE-2026-70788P3MEDIUMCVSS 6.5v11.2.25.0.0002026-08-18
CVE-2026-70788 [MEDIUM] CWE-284 CVE-2026-70788: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can
nvd
CVE-2026-70780P3MEDIUMCVSS 6.8v11.2.25.0.0002026-08-18
CVE-2026-70780 [MEDIUM] CWE-284 CVE-2026-70780: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Reporting e
nvd
CVE-2026-70753P3MEDIUMCVSS 6.3v11.2.25.0.0002026-08-18
CVE-2026-70753 [MEDIUM] CWE-284 CVE-2026-70753: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction
nvd
CVE-2026-70789P3MEDIUMCVSS 5.9v11.2.25.0.0002026-08-18
CVE-2026-70789 [MEDIUM] CWE-284 CVE-2026-70789: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interacti
nvd
CVE-2017-10358P3MEDIUMCVSS 6.4v11.1.22017-10-19
CVE-2017-10358 [MEDIUM] CVE-2017-10358: Vulnerability in the Oracle Hyperion Financial Reporting component of Oracle Hyperion (subcomponent:
Vulnerability in the Oracle Hyperion Financial Reporting component of Oracle Hyperion (subcomponent: Workspace). The supported version that is affected is 11.1.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. While the vulnerability is in Oracle Hyperion Financ
nvd
CVE-2026-70754P4MEDIUMCVSS 5.3v11.2.25.0.0002026-08-18
CVE-2026-70754 [MEDIUM] CWE-284 CVE-2026-70754: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can
nvd
CVE-2026-70768P4MEDIUMCVSS 6.1v11.2.25.0.0002026-08-18
CVE-2026-70768 [MEDIUM] CWE-284 CVE-2026-70768: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction
nvd
CVE-2026-70765P4MEDIUMCVSS 6.1v11.2.25.0.0002026-08-18
CVE-2026-70765 [MEDIUM] CWE-284 CVE-2026-70765: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction
nvd
CVE-2026-70759P4MEDIUMCVSS 5.4v11.2.25.0.0002026-08-18
CVE-2026-70759 [MEDIUM] CWE-284 CVE-2026-70759: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction
nvd
CVE-2026-70766P4MEDIUMCVSS 5.4v11.2.25.0.0002026-08-18
CVE-2026-70766 [MEDIUM] CWE-284 CVE-2026-70766: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction
nvd
CVE-2021-35665P4MEDIUMCVSS 6.1v11.2.6.02021-10-20
CVE-2021-35665 [MEDIUM] CVE-2021-35665: Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Repository)
Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that is affected is 11.2.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Financial Reporting. Successful attacks require human interaction from a person other th
nvd
CVE-2026-70784P4MEDIUMCVSS 5.3v11.2.25.0.0002026-08-18
CVE-2026-70784 [MEDIUM] CWE-284 CVE-2026-70784: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Reporting executes to compromise Oracle Hyperion Financial
nvd
CVE-2026-70758P4MEDIUMCVSS 5.3v11.2.25.0.0002026-08-18
CVE-2026-70758 [MEDIUM] CWE-284 CVE-2026-70758: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Reporting executes to compromise Oracle Hyperion Financial
nvd
CVE-2025-50108P4MEDIUMCVSS 5.4v11.2.20.0.0002025-07-15
CVE-2025-50108 [MEDIUM] CWE-284 CVE-2025-50108: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Work
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Workspace). The supported version that is affected is 11.2.20.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interacti
nvd
CVE-2021-27906P4MEDIUMCVSS 5.5v11.1.2.4v11.2.6.02021-03-19
CVE-2021-27906 [MEDIUM] CWE-789 CVE-2021-27906: A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
nvd
CVE-2021-27807P4MEDIUMCVSS 5.5v11.1.2.4v11.2.6.02021-03-19
CVE-2021-27807 [MEDIUM] CWE-834 CVE-2021-27807: A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects
A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
nvd
CVE-2026-70794P4MEDIUMCVSS 4.7v11.2.25.0.0002026-08-18
CVE-2026-70794 [MEDIUM] CWE-284 CVE-2026-70794: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Reporting executes to compromise Oracle Hyperion Financial
nvd
CVE-2026-70793P4MEDIUMCVSS 4.2v11.2.25.0.0002026-08-18
CVE-2026-70793 [MEDIUM] CWE-284 CVE-2026-70793: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability ca
nvd
CVE-2026-70785P4LOWCVSS 3.7v11.2.25.0.0002026-08-18
CVE-2026-70785 [LOW] CWE-284 CVE-2026-70785: Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can
nvd
CVE-2019-2959P4MEDIUMCVSS 4.2v11.1.2.42019-10-16
CVE-2019-2959 [MEDIUM] CVE-2019-2959: Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Security Mo
Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Security Models). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Financial Reporting. Successful attacks require human interaction from a person oth
nvd