Sceawere
Vulnerability Detail
CVE-2026-70785UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Reporting Information Disclosure
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.7
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Reporting
- Attack Type
- Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.7",
"pubDate": "2026-08-18T21:17:31.947Z",
"pubdate": "2026-08-18T21:17:31.947Z",
"executiveSummary": "A vulnerability has been identified within the Server component of the Oracle Hyperion Financial Reporting product, specifically affecting version 11.2.25.0.000. This security flaw introduces an information disclosure risk, allowing unauthorized entities to compromise confidentiality by reading a subset of sensitive enterprise data managed by the application. The vulnerability is classified as difficult to exploit due to specific conditions required for successful execution, yet it remains accessible remotely over the network without requiring authentication.\nThe risk implication centers on unauthorized data exposure, potentially granting attackers visibility into internal financial reporting metrics and business intelligence. Threat actors possessing network access via HTTP can attempt exploitation without prior system privileges or user interaction. Given the remote vector and lack of authentication prerequisites, organizations running the affected version face a moderate confidentiality risk that necessitates prompt administrative intervention and adherence to vendor patch advisories.",
"technicalDetails": "The vulnerability resides within the Server component of Oracle Hyperion Financial Reporting version 11.2.25.0.000. The underlying architectural flaw permits unauthorized read access to a specific subset of data accessible within the application framework. The attack surface is exposed over the network via the HTTP protocol, allowing remote entities to interact directly with the vulnerable endpoint without authenticating or possessing prior privileges.\nThe exploitation mechanism relies on high complexity conditions, indicating that successful attacks may require specific timing, precise input formatting, or particular environmental states to bypass intended access controls. An unauthenticated attacker initiates the attack flow by crafting targeted HTTP requests directed at the exposed Oracle Hyperion Financial Reporting server. If the high-complexity constraints are satisfied during the request lifecycle, the server improperly processes the input and returns restricted data subsets within the HTTP response.\nThe post-exploitation impact is strictly limited to confidentiality degradation, manifesting as unauthorized read access to application-accessible data. Integrity and availability metrics remain unaffected, as the vulnerability does not facilitate data modification, execution of arbitrary code, or denial of service conditions. The vector requires no user interaction (UI:N) and operates within a single security scope (S:U), meaning the compromise is confined to the application boundaries without escalating to the underlying operating system or hypervisor layers."
}