Sceawere

Vulnerability Detail

CVE-2026-70850UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Management Security Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
3
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Management
Attack Type
Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management.
Vector String
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 3.0 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.0",
  "pubDate": "2026-08-18T21:17:40.957Z",
  "pubdate": "2026-08-18T21:17:40.957Z",
  "executiveSummary": "A vulnerability exists within the Security component of Oracle Hyperion Financial Management, specifically affecting version 11.2.25.0.000.\nThis flaw is classified as a difficult-to-exploit vulnerability that requires high-privileged access and local logon capabilities to the underlying infrastructure where the product executes.\nSuccessful exploitation of this security issue enables an authenticated attacker with elevated privileges to compromise the Oracle Hyperion Financial Management application.\nThe primary impacts of a successful attack are limited to unauthorized update, insert, or delete access to a subset of accessible application data, alongside the capability to trigger a partial denial of service (partial DOS) affecting availability.\nThe severity of this issue is reflected by a CVSS 3.1 Base Score of 3.0, with impacts strictly confined to integrity and availability with no confidentiality impact.\nGiven the strict prerequisites—including local physical or logical access, high privileges, and high attack complexity—the overall risk to appropriately hardened enterprise environments is mitigated, though patching or applying designated vendor updates remains critical to preserve data integrity and service uptime.",
  "technicalDetails": "The vulnerability resides in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000.\nAccording to the CVSS 3.1 vector (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L), the attack vector (AV) is Local, indicating that the attacker must have direct or remote interactive logon access to the host infrastructure executing the target software.\nThe attack complexity (AC) is rated as High, meaning that successful exploitation requires specific preconditions, timing, or race conditions to be met, preventing straightforward or automated execution.\nPrivileges required (PR) are High, dictating that the threat actor must already possess administrative or highly privileged authorization within the local environment before initiating the attack sequence.\nUser interaction (UI) is None, indicating that the attack proceeds without requiring any actions from other system users.\nThe scope (S) is Unchanged, meaning the vulnerability is limited to the security context of the Oracle Hyperion Financial Management product itself without extending to underlying hypervisors or external components.\nThe attack flow requires the high-privileged adversary to successfully authenticate and log on to the host operating system or execution environment hosting Oracle Hyperion Financial Management.\nOnce established locally, the attacker leverages specialized administrative access or interacts with internal application processes and the vulnerable Security component to bypass intended authorization boundaries.\nPost-exploitation impacts manifest as unauthorized data manipulation capabilities—specifically insert, update, or delete operations—against accessible database records and repositories managed by Oracle Hyperion Financial Management.\nAdditionally, the malicious interaction can destabilize runtime execution threads or consume critical application resources, resulting in a partial denial of service condition that degrades the availability of the financial management system."
}
CVE-2026-70850: Oracle Hyperion Financial Management Security Vulnerability (LOW Severity, CVSS: 3.0) - Sceawere