Sceawere

Vulnerability Detail

CVE-2026-70843UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Management Security Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Management
Attack Type
Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data.
Vector String
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-08-18T21:17:40.010Z",
  "pubdate": "2026-08-18T21:17:40.010Z",
  "executiveSummary": "A vulnerability has been identified within the Security component of Oracle Hyperion Financial Management, specifically affecting version 11.2.25.0.000. This security flaw is classified as difficult to exploit but presents significant risks to data integrity and confidentiality. An unauthenticated attacker who has gained access to the physical communication segment attached to the underlying hardware hosting the Oracle Hyperion Financial Management application can leverage this flaw to compromise the system.\nSuccessful exploitation of this vulnerability allows unauthorized actors to perform critical operations on accessible data, including the unauthorized creation, deletion, or modification of critical data, as well as complete unauthorized access to all data accessible within Oracle Hyperion Financial Management. The severity of the vulnerability is reflected by a CVSS 3.1 Base Score of 6.8, with high impacts to both confidentiality and integrity, while availability remains unaffected. The attack vector requires adjacency (physical communication segment access) and high attack complexity, meaning exploitation prerequisites are relatively constrained, yet the potential damage to enterprise financial data remains severe.",
  "technicalDetails": "The vulnerability resides within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The root cause stems from insufficient validation or segmentation controls within the security mechanisms governing the physical communication segment to which the host hardware is attached. Because the vulnerability manifests at the network or physical segment layer, it bypasses standard application-layer boundary controls under specific conditions.\nThe attack vector is categorized as adjacent (AV:A), meaning the attacker must be positioned on the same physical or logical communication segment as the target hardware running Oracle Hyperion Financial Management. Furthermore, the attack complexity is rated as high (AC:H), indicating that successful exploitation requires specialized conditions, precise timing, or configuration nuances to be successfully orchestrated by the adversary.\nRegarding authentication and privileges, the vulnerability requires no privileges (PR:N) and no user interaction (UI:N), allowing unauthenticated entities residing on the adjacent network segment to initiate attack vectors against the vulnerable component. The scope (S:U) remains unchanged, indicating that the impact is confined to the vulnerable Oracle Hyperion Financial Management system itself rather than extending to core underlying hypervisor or host OS resources outside the application boundary.\nThe attack flow proceeds with the adversary establishing presence on the physical communication segment attached to the hardware executing Oracle Hyperion Financial Management. Due to the architectural exposure of the Security component, the attacker crafts specialized traffic or interactions targeted at the exposed interface. By overcoming the high attack complexity constraints, the adversary successfully circumvents authentication checks enforced by the Security component. Upon successful exploitation, the payload execution or unauthorized command sequence grants the attacker comprehensive access capabilities.\nThe post-exploitation impact yields severe confidentiality and integrity compromises (C:H/I:H/A:N). The attacker gains the capability to inspect sensitive financial records, proprietary corporate data, and restricted system parameters. Additionally, the adversary can execute unauthorized creation, modification, or deletion operations against critical data structures, leading to potential data corruption, falsification of financial statements, or total loss of data integrity within the Oracle Hyperion Financial Management ecosystem."
}
CVE-2026-70843: Oracle Hyperion Financial Management Security Vulnerability (MEDIUM Severity, CVSS: 6.8) - Sceawere