<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:netapp:bluexp:-:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3anetappbluexp-/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 13:08:57 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3anetappbluexp-/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Multiple Vulnerabilities in Oracle Hyperion</title><link>https://feed.craftedsignal.io/briefs/2026-09-oracle-hyperion-vulnerabilities/</link><pubDate>Wed, 16 Sep 2026 13:08:57 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-oracle-hyperion-vulnerabilities/</guid><description>Oracle Hyperion is affected by multiple security vulnerabilities (CVE-2024-21054, CVE-2024-21055) that allow remote attackers to compromise system confidentiality, integrity, and availability.</description><content:encoded><![CDATA[<p>Oracle Hyperion has been identified as containing multiple security vulnerabilities, tracked as CVE-2024-21054 and CVE-2024-21055. These flaws allow remote, anonymous, or authenticated attackers to perform unauthorized actions against affected systems. By exploiting these vulnerabilities, an adversary may gain the ability to bypass access controls, execute arbitrary code, or access sensitive data, resulting in a full compromise of the application's confidentiality, integrity, and availability. Organizations using Oracle Hyperion should evaluate their exposure and apply the necessary security patches or mitigations provided by the vendor to remediate these risks.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities allows for a total compromise of the Oracle Hyperion application. This includes potential unauthorized data access, manipulation of enterprise performance management data, and complete system takeover. Organizations in sectors relying on Hyperion for financial planning and analysis are at significant risk of operational disruption and data exfiltration if left unpatched.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification of all Oracle Hyperion instances within the production environment and apply the security updates provided by Oracle to address CVE-2024-21054 and CVE-2024-21055. Monitor web application access logs for unusual traffic patterns originating from external sources or unauthorized authenticated sessions.</p>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>vulnerability</category><category>enterprise-application</category></item></channel></rss>