logo

Oracle Hyperion 11 Directory Traversal

ID: 0001b12c-b551-5f14-8ab1-7f6de2ea1003

STIX ID: report--0001b12c-b551-5f14-8ab1-7f6de2ea1003

Feed Name: NCC Research

Threat Score
70/100

Date Published: 2025-12-02

Date Updated: 2026-08-01

...
...

Oracle published an advisory for Hyperion 11 (CVE-2013-3803) describing a directory traversal vulnerability in the /raframework/ihtml/GetResource endpoint that allows arbitrary file reads (demonstrated by retrieving /etc/passwd); affected 11.x releases were fixed in the July 2013 CPU.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.