Sceawere
Vulnerability Detail
CVE-2026-70769UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Reporting Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Reporting
- Attack Type
- Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-08-18T21:17:29.660Z",
"pubdate": "2026-08-18T21:17:29.660Z",
"executiveSummary": "A vulnerability affects the Server component of Oracle Hyperion Financial Reporting, specifically version 11.2.25.0.000. This security flaw allows an unauthenticated remote attacker with network access via the HTTP protocol to compromise the system.\nAlthough the vulnerability is characterized as difficult to exploit, successful exploitation yields severe consequences regarding data security. Attackers can gain unauthorized read access to critical and sensitive data, potentially exposing all information accessible to Oracle Hyperion Financial Reporting. Additionally, the vulnerability permits unauthorized modification, insertion, or deletion of a subset of the accessible data, undermining data integrity.\nThe inherent risks include severe breaches of confidentiality and partial compromise of data integrity within enterprise financial reporting environments. The attack vector is strictly network-based, requiring no prior authentication or user interaction. Consequently, organizations operating the affected version face potential unauthorized data exposure and tampering risks if defensive measures are not promptly applied.",
"technicalDetails": "The vulnerability resides within the Server component of Oracle Hyperion Financial Reporting version 11.2.25.0.000. The underlying root cause involves insufficient validation or authorization enforcement mechanisms within the application logic handling HTTP requests.\nThe attack flow begins when an unauthenticated threat actor leverages network access to transmit crafted HTTP payloads directly to the vulnerable Server component. Because the attack vector is network-based (AV:N), the adversary does not require local access or any prior privileges (PR:N) within the target environment. Furthermore, the exploitation process does not rely on user interaction (UI:N), allowing automated or manual exploitation directly against the exposed service endpoints.\nDespite being classified with a high attack complexity (AC:H), meaning successful exploitation requires precise timing, specific environmental conditions, or sophisticated payload construction, the resulting impact on the system is critical. Upon successful transmission and processing of the malicious HTTP request, the application fails to properly restrict access boundaries.\nThis failure permits the attacker to bypass authentication controls and execute unauthorized operations. In terms of post-exploitation impact, the confidentiality of the system is heavily compromised (C:H), granting the attacker complete or critical access to all data repositories and stores accessible via Oracle Hyperion Financial Reporting. Simultaneously, the integrity vector is affected (I:L), allowing the adversary to perform unauthorized data updates, insertions, or deletions against specific portions of the accessible dataset. The availability impact remains unaffected (A:N), as the attack focuses strictly on unauthorized data access and manipulation rather than denial of service."
}