Hyperion

Vendor:

First CVE: Jul 17, 2012 · Active for 14 years

23
Total CVEs
More Total CVEs than 95% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
4.6
Avg CVSS
Higher Avg CVSS than 5% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Hyperion over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 17, 2012
14 years ago
Most Recent CVE
Jul 18, 2023
1,102 days ago

CVE Severity & Scoring

Hyperion23 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network4 (17.4%)
Unknown19 (82.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (17.4%)
High0 (0.0%)
Unknown19 (82.6%)
User Interaction
None3 (13.0%)
Unknown19 (82.6%)
Required1 (4.3%)
Privileges Required
Low2 (8.7%)
High0 (0.0%)
None2 (8.7%)
Unknown19 (82.6%)

Top CVEs

Signals from CVEs in this product scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Unspecified vulnerability in the Hyperion BI+ component in Oracle Hyperion 11.1.1.3, 11.1.1.4.107 and earlier, 11.1.2.1.129 and earlier, and 11.1.2.2.305 and earlier allows remote
Jul 17, 20133.526NOYES
Vulnerability in the Hyperion Essbase Administration Services component of Oracle Hyperion (subcomponent: EAS Console). The supported version that is affected is 11.1.2.4. Easily e
Oct 17, 20187.724NONO
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that is affected is 11.2.13.0.000. Easily explo
Jul 18, 20238.522NONO
Vulnerability in the Hyperion Essbase Administration Services component of Oracle Hyperion (subcomponent: EAS Console). The supported version that is affected is 11.1.2.4. Easily e
Oct 17, 20186.121NONO
Vulnerability in the Hyperion Essbase Administration Services component of Oracle Hyperion (subcomponent: EAS Console). The supported version that is affected is 11.1.2.4. Easily e
Oct 17, 20185.820NONO
Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality, integrity, an
Apr 16, 20146.018NONO
Unspecified vulnerability in the Hyperion Analytic Provider Services component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality
Jul 17, 20143.517NONO
Unspecified vulnerability in the Hyperion Essbase component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect availability via unknown vectors related to A
Jul 17, 20145.016NONO
Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect confidentiality via unknown vectors rela
Apr 16, 20144.316NONO
Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect integrity via unknown vectors related to
Apr 16, 20144.316NONO

Exploit Exposure

Signals from CVEs in this product scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.3% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (23 CVEs).

Media Mentions

Signals from CVEs in this product scope (23 CVEs).

Top CNAs Publishing CVEs For Hyperion

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
11.2.13.0.00018.50.6%00
11.1.2.445.91.8%00
11.1.2.3174.11.5%00
11.1.2.2164.31.6%00
11.1.2.115.51.1%00
11.1.1.313.56.4%01
11.1.114.31.4%00