Oracle Hyperion Infrastructure Technology vulnerabilities
102 known vulnerabilities affecting oracle/hyperion_infrastructure_technology.
Total CVEs
102
CISA KEV
0
Public exploits
4
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH44MEDIUM38LOW8
Vulnerabilities
Page 3 of 6
CVE-2020-11656P3CRITICALCVSS 9.8v11.1.2.42020-04-09
CVE-2020-11656 [CRITICAL] CWE-416 CVE-2020-11656: In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an
In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.
nvd
CVE-2026-62467P3HIGHCVSS 7.7v11.2.25.0.0002026-08-18
CVE-2026-62467 [HIGH] CWE-284 CVE-2026-62467: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. While the vulnerability is i
nvd
CVE-2021-2351P3HIGHCVSS 7.5v11.2.7.02021-07-21
CVE-2021-2351 [HIGH] CWE-327 CVE-2021-2351: Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versi
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a perso
nvd
CVE-2018-14550P3HIGHCVSS 8.8v11.1.2.6.02019-07-10
CVE-2018-14550 [HIGH] CWE-787 CVE-2018-14550: An issue has been found in third-party PNM decoding associated with libpng 1.6.35. It is a stack-bas
An issue has been found in third-party PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow in the function get_token in pnm2png.c in pnm2png.
nvd
CVE-2026-62485P3HIGHCVSS 8.2v11.2.25.0.0002026-08-18
CVE-2026-62485 [HIGH] CWE-284 CVE-2026-62485: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require
nvd
CVE-2026-62545P3HIGHCVSS 7.5v11.2.25.0.0002026-08-18
CVE-2026-62545 [HIGH] CWE-284 CVE-2026-62545: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hy
nvd
CVE-2026-62551P3HIGHCVSS 7.3v11.2.25.0.0002026-08-18
CVE-2026-62551 [HIGH] CWE-284 CVE-2026-62551: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful
nvd
CVE-2026-62581P3HIGHCVSS 7.8v11.2.25.0.0002026-08-18
CVE-2026-62581 [HIGH] CWE-284 CVE-2026-62581: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to comp
nvd
CVE-2026-70971P3HIGHCVSS 7.1v11.2.25.0.0002026-08-18
CVE-2026-70971 [HIGH] CWE-284 CVE-2026-70971: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful
nvd
CVE-2019-5427P3HIGHCVSS 7.5v11.1.2.42019-04-22
CVE-2019-5427 [HIGH] CWE-776 CVE-2019-5427: c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration du
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
nvd
CVE-2020-5421P3MEDIUMCVSS 6.5v11.1.2.42020-09-19
CVE-2020-5421 [MEDIUM] CVE-2020-5421: In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and olde
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
nvd
CVE-2026-70972P3MEDIUMCVSS 6.8v11.2.25.0.0002026-08-18
CVE-2026-70972 [MEDIUM] CWE-284 CVE-2026-70972: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Success
nvd
CVE-2026-70968P3MEDIUMCVSS 6.5v11.2.25.0.0002026-08-18
CVE-2026-70968 [MEDIUM] CWE-284 CVE-2026-70968: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successfu
nvd
CVE-2026-62576P3MEDIUMCVSS 6.5v11.2.25.0.0002026-08-18
CVE-2026-62576 [MEDIUM] CWE-284 CVE-2026-62576: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Hyperion Infrastructure Technology. Success
nvd
CVE-2026-62522P3HIGHCVSS 7.1v11.2.25.0.0002026-08-18
CVE-2026-62522 [HIGH] CWE-284 CVE-2026-62522: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. While the vulnerability
nvd
CVE-2026-62506P3MEDIUMCVSS 6.5v11.2.25.0.0002026-08-18
CVE-2026-62506 [MEDIUM] CWE-284 CVE-2026-62506: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of th
nvd
CVE-2026-62555P3MEDIUMCVSS 6.5v11.2.25.0.0002026-08-18
CVE-2026-62555 [MEDIUM] CWE-284 CVE-2026-62555: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via SQL to compromise Oracle Hyperion Infrastructure Technology. Successfu
nvd
CVE-2020-13871P3HIGHCVSS 7.5v11.1.2.42020-06-06
CVE-2020-13871 [HIGH] CWE-416 CVE-2020-13871: SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite fo
SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late.
nvd
CVE-2020-9327P3HIGHCVSS 7.5v11.1.2.42020-02-21
CVE-2020-9327 [HIGH] CWE-476 CVE-2020-9327: In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and
In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault because of generated column optimizations.
nvd
CVE-2026-62523P3MEDIUMCVSS 6.5v11.2.25.0.0002026-08-18
CVE-2026-62523 [MEDIUM] CWE-284 CVE-2026-62523: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks requ
nvd