Sceawere
Vulnerability Detail
CVE-2026-70847UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Management Security Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Management
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data.
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-08-18T21:17:40.567Z",
"pubdate": "2026-08-18T21:17:40.567Z",
"executiveSummary": "A security vulnerability has been identified within the Oracle Hyperion Financial Management product of Oracle Hyperion, specifically affecting the Security component in version 11.2.25.0.000. This vulnerability presents an inherent risk to enterprise infrastructure by allowing a low-privileged attacker with prior logon access to the underlying execution environment to successfully compromise the application. The primary impact of successful exploitation is localized to confidentiality, granting unauthorized access to critical data or complete access to all data accessible by Oracle Hyperion Financial Management. Furthermore, due to the nature of the integration and architectural design, attacks against this vulnerability introduce a scope change, meaning that the successful exploitation of the Oracle Hyperion Financial Management component can significantly impact additional, interconnected products within the enterprise ecosystem. The attack vector is classified as local, requiring low privileges and no user interaction, making it an efficient vector for insider threats or compromised user accounts that have successfully established a foothold on the host infrastructure.",
"technicalDetails": "The vulnerability resides within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. According to the CVSS 3.1 vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N), the vulnerability is characterized by a Local attack vector (AV:L), meaning the adversary must already possess physical or logical access to the infrastructure where the Oracle Hyperion Financial Management software executes. The attack complexity is rated as Low (AC:L), indicating that no specialized race conditions, memory corruption tuning, or complex cryptographic bypasses are required to achieve exploitation once the prerequisite access is obtained. Privilege requirements are Low (PR:L), signifying that an attacker needs only standard, unprivileged user credentials or a basic execution context on the host system to initiate the attack sequence. User interaction is not required (UI:N), allowing automated or silent execution by the malicious actor.\nThe attack flow begins when the low-privileged attacker leverages their existing logon access to the target infrastructure hosting Oracle Hyperion Financial Management. By interacting locally with the vulnerable Security component, the attacker exploits underlying logic flaws or improper access controls governing sensitive data stores or inter-process communications. Because the vulnerability exhibits a scope change (S:C), the compromise is not strictly contained within the security boundary of Oracle Hyperion Financial Management; rather, the successful exploitation ripples outward, compromising the security posture of additional, dependent or integrated products residing within the broader administrative or operational domain.\nThe post-exploitation impact is heavily weighted toward a severe breach of confidentiality (C:H). Upon successful execution of the attack payload, the adversary gains unauthorized read access to critical enterprise data, potentially escalating their operational view to encompass complete access to all data repositories, financial records, and operational metrics accessible by the Oracle Hyperion Financial Management application and its associated trust domains. Integrity and availability impacts remain unaffected (I:N/A:N), as the primary vector focuses entirely on unauthorized information disclosure across the affected application scope and impacted secondary products."
}