CVE-2013-3803

Oracle Hyperion <11.1.2.305 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-3803. PoCs published by Richard Warren.

AI-analyzed exploit summary This is a writeup detailing a directory traversal vulnerability in Oracle Hyperion 11. The vulnerability allows an attacker to read arbitrary files on the server by manipulating the ResourceName parameter in a GET request.

Description

Unspecified vulnerability in the Hyperion BI+ component in Oracle Hyperion 11.1.1.3, 11.1.1.4.107 and earlier, 11.1.2.1.129 and earlier, and 11.1.2.2.305 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Intelligence Service.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Richard Warren · textwebappswindows
https://www.exploit-db.com/exploits/27291

This is a writeup detailing a directory traversal vulnerability in Oracle Hyperion 11. The vulnerability allows an attacker to read arbitrary files on the server by manipulating the ResourceName parameter in a GET request.

Classification
Writeup 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Oracle Hyperion 11.1.1.3, 11.1.1.4.107 and earlier, 11.1.2.1.129 and earlier, and 11.1.2.2.305 and earlier
No auth needed
Prerequisites: Network access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Broken Link vdb-entry x_refsource_osvdb
http://osvdb.org/95277
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/85664
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/61204
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1028794
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/54220

Scores

EPSS 0.0643
EPSS Percentile 92.8%

Details

Status published
Products (2)
oracle/hyperion 11.1.1.3
oracle/hyperion 11.1.1.4 - 11.1.1.4.107
Published Jul 17, 2013
Tracked Since Feb 18, 2026