Hyperion EPM General (MOSC)

MOSC Banner

Hyperion 11.1.2.4. and CVE-2022-23307

Hello Community,

Anyone have seen this CVE update? It goes like this:

" CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists."

That means that previous versions are also impacted and that the only path of action is to upgrade to the latest hyperion 11.2 where there is an actual fix or mitigation activities, am I getting this right?


Thanks,

Santiago

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center