Hyperion Financial Reporting

Vendor:

First CVE: Jul 21, 2016 · Active for 10 years

13
Total CVEs
More Total CVEs than 92% of tracked products
1.9
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 35% of tracked products
7.7%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Hyperion Financial Reporting over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 21, 2016
10 years ago
Most Recent CVE
Jul 15, 2025
378 days ago

CVE Severity & Scoring

Hyperion Financial Reporting13 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local2 (15.4%)
Network11 (84.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None6 (46.2%)
Unknown0 (0.0%)
Required7 (53.8%)
Privileges Required
Low2 (15.4%)
High2 (15.4%)
None9 (69.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's
Apr 29, 20206.195YESYES
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
Apr 17, 20199.835NONO
Unspecified vulnerability in the Hyperion Financial Reporting component in Oracle Hyperion 11.1.2.4 allows remote attackers to affect confidentiality, integrity, and availability v
Jul 21, 20169.833NONO
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker co
Nov 12, 20207.529NONO
Vulnerability in the Hyperion Financial Reporting component of Oracle Hyperion (subcomponent: Security Models). The supported version that is affected is 11.1.2. Easily exploitable
Jul 18, 20188.625NONO
Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that is affected is 11.2.6.0. Easily exploitable vulnera
Oct 20, 20216.121NONO
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
Mar 19, 20215.521NONO
A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
Mar 19, 20215.521NONO
Vulnerability in the Oracle Hyperion Financial Reporting component of Oracle Hyperion (subcomponent: Security Models). The supported version that is affected is 11.1.2. Easily expl
Oct 19, 20177.520NONO
Vulnerability in the Oracle Hyperion Financial Reporting component of Oracle Hyperion (subcomponent: Workspace). The supported version that is affected is 11.1.2. Easily exploitabl
Oct 19, 20176.419NONO

Exploit Exposure

Signals from CVEs in this product scope (13 CVEs).

CISA KEV
1 CVE
7.7% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.7% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (13 CVEs).

Media Mentions

Signals from CVEs in this product scope (13 CVEs).

Top CNAs Publishing CVEs For Hyperion Financial Reporting

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
11.2.6.046.74.2%00
11.2.5.017.510.7%00
11.2.20.0.00015.40.2%00
11.1.2.486.314.7%11
11.1.237.52.4%00