Sceawere

Vulnerability Detail

CVE-2026-70743UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Reporting Server Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Reporting
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Reporting.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-08-18T21:17:27.113Z",
  "pubdate": "2026-08-18T21:17:27.113Z",
  "executiveSummary": "An easily exploitable security vulnerability affects the Oracle Hyperion Financial Reporting product, specifically within the Server component. The vulnerability impacts version 11.2.25.0.000 and can be leveraged by an unauthenticated attacker with network access via the HTTPS protocol.\nSuccessful exploitation of this flaw grants the adversary unauthorized access to critical data or complete access to all data accessible by Oracle Hyperion Financial Reporting, severely impacting confidentiality. Additionally, it enables an unauthorized actor to trigger a partial denial of service (partial DOS), degrading system availability.\nThe vulnerability carries a CVSS 3.1 Base Score of 8.2 with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L, highlighting low attack complexity and the absence of required privileges or user interaction.\nOrganizations utilizing the affected Oracle Hyperion Financial Reporting version face significant risk regarding data exposure and service disruption, necessitating immediate defensive measures and patch deployment upon availability.",
  "technicalDetails": "The vulnerability resides within the Server component of Oracle Hyperion Financial Reporting version 11.2.25.0.000, exposing attack surfaces to remote network vectors.\nThe attack flow begins with an unauthenticated remote attacker establishing network connectivity to the vulnerable Oracle Hyperion Financial Reporting Server over HTTPS. Because the vulnerability requires low attack complexity and demands zero privileges (PR:N) or user interaction (UI:N), the attacker can directly interact with the exposed endpoints without prior authentication or credential theft.\nUpon reaching the vulnerable component, the attacker transmits crafted requests that bypass existing access controls or logic constraints. This improper handling allows the adversary to read sensitive enterprise financial data, resulting in a high confidentiality impact (C:H) characterized by unauthorized access to critical or complete application data repositories.\nConcurrently, the malformed or excessive interaction with the vulnerable Server component exhausts or disrupts specific processing threads or resources, leading to a partial denial of service (A:L) condition that affects the operational availability of the Oracle Hyperion Financial Reporting application.\nThe scope (S:U) remains unchanged, indicating that the impact is constrained to the vulnerable Oracle Hyperion Financial Reporting component itself without directly compromising underlying host operating system resources beyond the application boundary."
}
CVE-2026-70743: Oracle Hyperion Financial Reporting Server Vulnerability (HIGH Severity, CVSS: 8.2) - Sceawere