Oracle Hyperion Planning vulnerabilities

6 known vulnerabilities affecting oracle/hyperion_planning.

Total CVEs
6
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2021-45105MEDIUMCVSS 5.9fixed in 11.2.8.02021-12-18
CVE-2021-45105 [MEDIUM] CWE-20 CVE-2021-45105: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from u Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
nvd
CVE-2020-14764MEDIUMCVSS 4.2v11.1.2.42020-10-21
CVE-2020-14764 [MEDIUM] CVE-2020-14764: Vulnerability in the Hyperion Planning product of Oracle Hyperion (component: Application Developmen Vulnerability in the Hyperion Planning product of Oracle Hyperion (component: Application Development Framework). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Planning. Successful attacks require human interaction from a person other
nvd
CVE-2019-2904CRITICALCVSS 9.8v11.1.2.42019-10-16
CVE-2019-2904 [CRITICAL] CVE-2019-2904: Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF F Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and ADF. Successful attacks of this vulnerabil
nvd
CVE-2019-2861MEDIUMCVSS 4.2PoCv11.1.2.42019-07-23
CVE-2019-2861 [MEDIUM] CWE-611 CVE-2019-2861: Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Planning. Successful attacks require human interaction from a person other
nvd
CVE-2019-2770MEDIUMCVSS 4.5v11.1.2.42019-07-23
CVE-2019-2770 [MEDIUM] CVE-2019-2770: Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Smart View Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Smart View). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Planning. Successful attacks require human interaction from a person other than th
nvd
CVE-2018-2733HIGHCVSS 7.6v11.1.2.4.0072018-01-18
CVE-2018-2733 [HIGH] CVE-2018-2733: Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). The supported version that is affected is 11.1.2.4.007. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Planning. Successful attacks require human interaction from a person other than
nvd