Oracle Hyperion Infrastructure Technology vulnerabilities
102 known vulnerabilities affecting oracle/hyperion_infrastructure_technology.
Total CVEs
102
CISA KEV
0
Public exploits
4
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH44MEDIUM38LOW8
Vulnerabilities
Page 2 of 6
CVE-2026-70958P3CRITICALCVSS 9.6v11.2.25.0.0002026-08-18
CVE-2026-70958 [CRITICAL] CWE-601 CVE-2026-70958: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Succes
nvd
CVE-2026-62535P3HIGHCVSS 8.6v11.2.25.0.0002026-08-18
CVE-2026-62535 [HIGH] CWE-284 CVE-2026-62535: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Hyperion Infrastructure Technolo
nvd
CVE-2026-62531P3HIGHCVSS 8.1v11.2.25.0.0002026-08-18
CVE-2026-62531 [HIGH] CWE-284 CVE-2026-62531: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks
nvd
CVE-2026-62501P3HIGHCVSS 8.1v11.2.25.0.0002026-08-18
CVE-2026-62501 [HIGH] CWE-284 CVE-2026-62501: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of thi
nvd
CVE-2019-17563P3HIGHCVSS 7.5v11.1.2.42019-12-23
CVE-2019-17563 [HIGH] CWE-384 CVE-2019-17563: When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.
nvd
CVE-2026-62477P3HIGHCVSS 8.1v11.2.25.0.0002026-08-18
CVE-2026-62477 [HIGH] CWE-284 CVE-2026-62477: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this
nvd
CVE-2026-62502P3HIGHCVSS 8.1v11.2.25.0.0002026-08-18
CVE-2026-62502 [HIGH] CWE-284 CVE-2026-62502: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this v
nvd
CVE-2026-70957P3HIGHCVSS 8.1v11.2.25.0.0002026-08-18
CVE-2026-70957 [HIGH] CWE-284 CVE-2026-70957: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful
nvd
CVE-2026-62471P3HIGHCVSS 8.1v11.2.25.0.0002026-08-18
CVE-2026-62471 [HIGH] CWE-284 CVE-2026-62471: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of thi
nvd
CVE-2019-12402P3HIGHCVSS 7.5v11.1.2.42019-08-30
CVE-2019-12402 [HIGH] CWE-835 CVE-2019-12402: The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get int
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
nvd
CVE-2026-70964P3HIGHCVSS 8.2v11.2.25.0.0002026-08-18
CVE-2026-70964 [HIGH] CWE-284 CVE-2026-70964: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. While the
nvd
CVE-2026-60393P3HIGHCVSS 7.5v11.2.25.0.0002026-08-18
CVE-2026-60393 [HIGH] CWE-200 CVE-2026-60393: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks o
nvd
CVE-2026-62550P3HIGHCVSS 7.5v11.2.25.0.0002026-08-18
CVE-2026-62550 [HIGH] CWE-284 CVE-2026-62550: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful
nvd
CVE-2026-62554P3HIGHCVSS 7.5v11.2.25.0.0002026-08-18
CVE-2026-62554 [HIGH] CWE-284 CVE-2026-62554: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful
nvd
CVE-2026-62552P3HIGHCVSS 7.5v11.2.25.0.0002026-08-18
CVE-2026-62552 [HIGH] CWE-284 CVE-2026-62552: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful
nvd
CVE-2026-70973P3HIGHCVSS 7.5v11.2.25.0.0002026-08-18
CVE-2026-70973 [HIGH] CWE-306 CVE-2026-70973: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successfu
nvd
CVE-2026-62481P3HIGHCVSS 7.5v11.2.25.0.0002026-08-18
CVE-2026-62481 [HIGH] CWE-284 CVE-2026-62481: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this
nvd
CVE-2026-62538P3HIGHCVSS 7.4v11.2.25.0.0002026-08-18
CVE-2026-62538 [HIGH] CWE-284 CVE-2026-62538: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Infrastructure Technology. Success
nvd
CVE-2026-62492P3HIGHCVSS 7.4v11.2.25.0.0002026-08-18
CVE-2026-62492 [HIGH] CWE-284 CVE-2026-62492: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of
nvd
CVE-2026-70959P3HIGHCVSS 8.1v11.2.25.0.0002026-08-18
CVE-2026-70959 [HIGH] CWE-284 CVE-2026-70959: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful
nvd