Oracle
Oracle Hyperion: vulnerabilities and CVEs
Oracle Hyperion has 25 published vulnerabilities, 1 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs25
Last 12 months1
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21979 | Medium (4.2) | 0.13% | — | Jan 20, 2026 | Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). The supported version that is affected is 25.04.07. Easily exploitable vulnerability allows high… |
| CVE-2024-4175 | Medium (5.4) | 0.31% | — | Apr 25, 2024 | Unicode transformation vulnerability in Hyperion affecting version 2.0.15. This vulnerability could allow an attacker to send a malicious payload with Unicode characters that will be replaced by ASCII characters. |
| CVE-2023-22062 | High (8.5) | 0.62% | — | Jul 18, 2023 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that is affected is 11.2.13.0.000. Easily exploitable vulnerability allows low… |
| CVE-2018-3142 | High (7.7) | 2.0% | — | Oct 17, 2018 | Vulnerability in the Hyperion Essbase Administration Services component of Oracle Hyperion (subcomponent: EAS Console). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows low… |
| CVE-2018-3141 | Medium (5.8) | 2.0% | — | Oct 17, 2018 | Vulnerability in the Hyperion Essbase Administration Services component of Oracle Hyperion (subcomponent: EAS Console). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows… |
| CVE-2018-3140 | Medium (6.1) | 1.5% | — | Oct 17, 2018 | Vulnerability in the Hyperion Essbase Administration Services component of Oracle Hyperion (subcomponent: EAS Console). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows… |
| CVE-2015-4823 | Low (1.2) | 0.37% | — | Oct 21, 2015 | Unspecified vulnerability in the Hyperion Installation Technology component in Oracle Hyperion 11.1.2.3 allows local users to affect confidentiality via unknown vectors related to Essbase Rapid Deploy. |
| CVE-2015-4773 | Medium (4) | 1.5% | — | Jul 16, 2015 | Unspecified vulnerability in the Hyperion Common Security component in Oracle Hyperion 11.1.2.2, 11.1.2.3, and 11.1.2.4 allows remote authenticated users to affect availability via unknown vectors related to User… |
| CVE-2015-2592 | Low (3.5) | 1.2% | — | Jul 16, 2015 | Unspecified vulnerability in the Hyperion Enterprise Performance Management Architect component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect integrity via unknown vectors related… |
| CVE-2015-2584 | Medium (4) | 1.3% | — | Jul 16, 2015 | Unspecified vulnerability in the Hyperion Enterprise Performance Management Architect component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect integrity via unknown vectors related… |
| CVE-2015-0509 | Medium (4.3) | 1.5% | — | Apr 16, 2015 | Unspecified vulnerability in the Oracle Hyperion BI+ component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect integrity via unknown vectors related to Reporting and Analysis. |
| CVE-2014-3707 | Medium (4.3) | 5.1% | — | Nov 15, 2014 | The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that… |
| CVE-2014-4271 | Medium (5) | 2.9% | — | Jul 17, 2014 | Unspecified vulnerability in the Hyperion Essbase component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect availability via unknown vectors related to Agent. |
| CVE-2014-4270 | Medium (4) | 1.9% | — | Jul 17, 2014 | Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality via unknown vectors related to User Interface, a… |
| CVE-2014-4269 | Medium (4) | 1.9% | — | Jul 17, 2014 | Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality via unknown vectors related to User Interface, a… |
| CVE-2014-4246 | Low (3.5) | 1.7% | — | Jul 17, 2014 | Unspecified vulnerability in the Hyperion Analytic Provider Services component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality via vectors related to SVP. |
| CVE-2014-4206 | Low (3.3) | 0.36% | — | Jul 17, 2014 | Unspecified vulnerability in the Hyperion Enterprise Performance Management Architect component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows local users to affect integrity and availability via unknown vectors… |
| CVE-2014-4203 | Medium (4.1) | 0.31% | — | Jul 17, 2014 | Unspecified vulnerability in the Hyperion Enterprise Performance Management Architect component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows local users to affect confidentiality, integrity, and availability via… |
| CVE-2014-0436 | Medium (4.3) | 1.4% | — | Jul 17, 2014 | Unspecified vulnerability in the Hyperion BI+ component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect integrity via unknown vectors related to Web Analysis. |
| CVE-2014-2455 | Medium (6) | 0.98% | — | Apr 16, 2014 | Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors… |
| CVE-2014-2454 | Medium (4.3) | 1.0% | — | Apr 16, 2014 | Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect confidentiality via unknown vectors related to User Interface. |
| CVE-2014-2453 | Medium (4.3) | 1.0% | — | Apr 16, 2014 | Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect integrity via unknown vectors related to User Interface. |
| CVE-2014-0367 | Medium (5.5) | 1.1% | — | Jan 15, 2014 | Unspecified vulnerability in the Hyperion Essbase Administration Services component in Oracle Hyperion 11.1.2.1, 11.1.2.2, and 11.1.2.3 allows remote authenticated users to affect confidentiality and integrity via… |
| CVE-2013-3803 | Low (3.5) | 6.4% | — | Jul 17, 2013 | Unspecified vulnerability in the Hyperion BI+ component in Oracle Hyperion 11.1.1.3, 11.1.1.4.107 and earlier, 11.1.2.1.129 and earlier, and 11.1.2.2.305 and earlier allows remote authenticated users to affect… |
| CVE-2012-1729 | Medium (4.3) | 1.4% | — | Jul 17, 2012 | Unspecified vulnerability in the Hyperion BI+ component in Oracle Hyperion 11.1.1.3 and earlier allows remote attackers to affect integrity via unknown vectors related to UI and Visualization. |