Oracle Hyperion Infrastructure Technology vulnerabilities
102 known vulnerabilities affecting oracle/hyperion_infrastructure_technology.
Total CVEs
102
CISA KEV
0
Public exploits
4
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH44MEDIUM38LOW8
Vulnerabilities
Page 4 of 6
CVE-2026-70967P3HIGHCVSS 7.1v11.2.25.0.0002026-08-18
CVE-2026-70967 [HIGH] CWE-284 CVE-2026-70967: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to comp
nvd
CVE-2026-62537P3HIGHCVSS 7.1v11.2.25.0.0002026-08-18
CVE-2026-62537 [HIGH] CWE-284 CVE-2026-62537: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to comp
nvd
CVE-2026-62536P3HIGHCVSS 7.1v11.2.25.0.0002026-08-18
CVE-2026-62536 [HIGH] CWE-284 CVE-2026-62536: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to comp
nvd
CVE-2020-11655P3HIGHCVSS 7.5v11.1.2.42020-04-09
CVE-2020-11655 [HIGH] CWE-665 CVE-2020-11655: SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malfo
SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.
nvd
CVE-2020-27218P4MEDIUMCVSS 4.8v11.1.2.6.02020-11-28
CVE-2020-27218 [MEDIUM] CWE-226 CVE-2020-27218: In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.al
In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the applicati
nvd
CVE-2026-62558P4MEDIUMCVSS 6.3v11.2.25.0.0002026-08-18
CVE-2026-62558 [MEDIUM] CWE-284 CVE-2026-62558: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to
nvd
CVE-2026-62509P4MEDIUMCVSS 5.3v11.2.25.0.0002026-08-18
CVE-2026-62509 [MEDIUM] CWE-284 CVE-2026-62509: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of thi
nvd
CVE-2026-62566P4MEDIUMCVSS 5.3v11.2.25.0.0002026-08-18
CVE-2026-62566 [MEDIUM] CWE-284 CVE-2026-62566: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successf
nvd
CVE-2026-62510P4MEDIUMCVSS 5.3v11.2.25.0.0002026-08-18
CVE-2026-62510 [MEDIUM] CWE-284 CVE-2026-62510: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successf
nvd
CVE-2026-62579P4MEDIUMCVSS 5.3v11.2.25.0.0002026-08-18
CVE-2026-62579 [MEDIUM] CWE-284 CVE-2026-62579: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successf
nvd
CVE-2026-62572P4MEDIUMCVSS 6.5v11.2.25.0.0002026-08-18
CVE-2026-62572 [MEDIUM] CWE-284 CVE-2026-62572: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to co
nvd
CVE-2026-62499P4MEDIUMCVSS 6.1v11.2.25.0.0002026-08-18
CVE-2026-62499 [MEDIUM] CWE-284 CVE-2026-62499: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks requ
nvd
CVE-2026-70961P4MEDIUMCVSS 6.1v11.2.25.0.0002026-08-18
CVE-2026-70961 [MEDIUM] CWE-284 CVE-2026-70961: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successf
nvd
CVE-2026-62568P4MEDIUMCVSS 6.1v11.2.25.0.0002026-08-18
CVE-2026-62568 [MEDIUM] CWE-284 CVE-2026-62568: Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successf
nvd
CVE-2020-1935P4MEDIUMCVSS 4.8v11.1.2.42020-02-24
CVE-2020-1935 [MEDIUM] CWE-444 CVE-2020-1935: In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing cod
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encodi
nvd
CVE-2019-7317P4MEDIUMCVSS 5.3v11.2.6.02019-02-04
CVE-2019-7317 [MEDIUM] CWE-416 CVE-2019-7317: png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_fu
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
nvd
CVE-2020-14854P4MEDIUMCVSS 6.1v11.1.2.42020-10-21
CVE-2020-14854 [MEDIUM] CVE-2020-14854: Vulnerability in the Hyperion Infrastructure Technology product of Oracle Hyperion (component: UI an
Vulnerability in the Hyperion Infrastructure Technology product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Infrastructure Technology. Successful attacks require human interaction
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1v11.2.7.02019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2019-12415P4MEDIUMCVSS 5.5v11.1.2.42019-10-23
CVE-2019-12415 [MEDIUM] CWE-611 CVE-2019-12415: In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Ex
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
nvd
CVE-2021-2445P4MEDIUMCVSS 5.7v11.2.5.02021-07-21
CVE-2021-2445 [MEDIUM] CVE-2021-2445: Vulnerability in the Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifec
Vulnerability in the Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.5.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Infrastructure Technology. Successful attacks require human interaction
nvd