Sceawere

Vulnerability Detail

CVE-2026-70851UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Management Denial of Service

Vulnerability Metadata

Severity
Low
Score / CVSS
3.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Management
Attack Type
Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management.
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.1",
  "pubDate": "2026-08-18T21:17:41.087Z",
  "pubdate": "2026-08-18T21:17:41.087Z",
  "executiveSummary": "A denial of service vulnerability exists within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. This security flaw allows an authenticated attacker with low privileges and network access via the HTTP protocol to compromise the availability of the targeted application. Successful exploitation of this vulnerability results in an unauthorized partial denial of service condition, impacting the operational availability of Oracle Hyperion Financial Management without affecting data confidentiality or integrity. The vulnerability is characterized by a CVSS 3.1 Base Score of 3.1 with an availability-only impact vector. Exploitation requires high attack complexity, meaning the attacker must satisfy specific preconditions or execute precise timing to successfully trigger the flaw over the network. Risk implications are constrained to service degradation or partial interruption, making it a lower severity availability risk that primarily threatens business continuity and application uptime rather than data security.",
  "technicalDetails": "The vulnerability resides in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000, specifically within routines handling HTTP-based network transactions and authorization logic. The root cause stems from insufficient validation or resource management limitations when processing specific inputs or sequences over the HTTP protocol, which can be induced to exhaust or disrupt targeted application resources. The attack flow begins with a threat actor possessing network access to the exposed Oracle Hyperion Financial Management service endpoints. Because the attack vector is network-based (AV:N), the adversary interacts directly with the vulnerable HTTP interface. The attacker must possess low privileges (PR:L), necessitating valid user authentication within the system, and no user interaction (UI:N) is required to facilitate the attack. Due to the high attack complexity (AC:H), the exploitation method requires precise conditions, specialized request structuring, or specific environmental states to successfully bypass internal checks and trigger the fault condition. Once the requisite preconditions are met, the payload or triggering sequence reaches the vulnerable Security component, where it induces an exception, excessive resource consumption, or instability. This results in a partial denial of service (S:U, C:N, I:N, A:L), impairing the normal execution flow and limiting accessibility to specific functions or services within Oracle Hyperion Financial Management. Post-exploitation impact is strictly contained to the availability vector, causing localized service degradation or functional interruption without granting unauthorized read or write access to underlying data stores, administrative privileges, or remote code execution capabilities."
}
CVE-2026-70851: Oracle Hyperion Financial Management Denial of Service (LOW Severity, CVSS: 3.1) - Sceawere