Hyperion Infrastructure Technology
Vendor:
First CVE: Feb 4, 2019 · Active for 7 years
35
Total CVEs
More Total CVEs than 96% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Hyperion Infrastructure Technology over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 4, 2019
7 years ago
Most Recent CVE
Apr 21, 2026
94 days ago
CVE Severity & Scoring
Hyperion Infrastructure Technology35 CVEs
46%
37%
14%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local5 (14.3%)
Network30 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (68.6%)
High11 (31.4%)
Unknown0 (0.0%)
User Interaction
None20 (57.1%)
Unknown0 (0.0%)
Required15 (42.9%)
Privileges Required
Low7 (20.0%)
High6 (17.1%)
None22 (62.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-2729CRITICAL Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and | Jun 19, 2019 | 9.8 | 89 | NO | YES |
CVE-2020-11984CRITICAL Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE | Aug 7, 2020 | 9.8 | 83 | NO | YES |
CVE-2021-45105MEDIUM Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit | Dec 18, 2021 | 5.9 | 76 | NO | NO |
CVE-2021-4104HIGH JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName | Dec 14, 2021 | 7.5 | 70 | NO | NO |
CVE-2022-23305CRITICAL By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message conv | Jan 18, 2022 | 9.8 | 68 | NO | NO |
CVE-2020-9490HIGH Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to | Aug 7, 2020 | 7.5 | 68 | NO | NO |
CVE-2022-23302HIGH JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration refere | Jan 18, 2022 | 8.8 | 63 | NO | NO |
CVE-2022-23307HIGH CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exi | Jan 18, 2022 | 8.8 | 57 | NO | NO |
CVE-2020-11993HIGH Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong conn | Aug 7, 2020 | 7.5 | 51 | NO | NO |
CVE-2019-13990CRITICAL initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description. | Jul 26, 2019 | 9.8 | 40 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (35 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
5.7% of CVEs· 97th percentile
ExploitDB
1 CVE
2.9% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (35 CVEs).
Media Mentions
Signals from CVEs in this product scope (35 CVEs).
Top CNAs Publishing CVEs For Hyperion Infrastructure Technology
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 11.2.7.0 | 2 | 7.2 | 2.3% | 0 | 0 |
| 11.2.6.0 | 1 | 5.3 | 9.4% | 0 | 0 |
| 11.2.5.0 | 3 | 6.9 | 30.2% | 0 | 1 |
| 11.2.24.0 | 1 | 5.2 | 0.2% | 0 | 0 |
| 11.1.2.6.0 | 2 | 6.8 | 5.8% | 0 | 0 |
| 11.1.2.4 | 20 | 7.0 | 21.1% | 0 | 2 |