Sceawere

Vulnerability Detail

CVE-2026-70853UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Management Security Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
3.3
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Management
Attack Type
Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management.
Vector String
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 3.3 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.3",
  "pubDate": "2026-08-18T21:17:41.347Z",
  "pubdate": "2026-08-18T21:17:41.347Z",
  "executiveSummary": "A vulnerability exists within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. This security flaw is characterized as difficult to exploit and requires an attacker to possess high-level privileges alongside network access via HTTP.\nSuccessful exploitation of this vulnerability compromises the Oracle Hyperion Financial Management application by enabling unauthorized read access to a subset of sensitive data, as well as the capability to induce a partial denial of service (partial DOS) condition against the targeted system.\nThe assigned CVSS 3.1 base score is 3.3, reflecting moderate-low severity with targeted impacts exclusively on confidentiality and availability. The attack vector is network-based, but the prerequisite high privilege requirements and high attack complexity serve to mitigate the overall risk profile under standard operational conditions.",
  "technicalDetails": "The vulnerability resides within the Security component of Oracle Hyperion Financial Management, specifically affecting version 11.2.25.0.000. The root cause stems from insufficient validation and access controls within the targeted security subroutines exposed over the application's HTTP interface.\nExploitation of this vulnerability requires the adversary to authenticate and interact with the application through the network via HTTP, leveraging high-level administrative or privileged access credentials. Due to the high attack complexity metric (AC:H), successful exploitation demands precise timing, specific environmental prerequisites, or complex payload sequencing orchestrated by the attacker.\nThe attack flow proceeds as follows: First, the authenticated attacker with high privileges crafts a specialized HTTP request designed to interact with vulnerable functions within the Security component. Second, the request traverses the network boundary and reaches the Oracle Hyperion Financial Management application server. Third, the application processes the input without adequate validation or restriction, leading to an improper handling of security state or memory resources.\nAs a result of this flawed processing, the attacker achieves unauthorized read access to a specific subset of data accessible within Oracle Hyperion Financial Management, violating confidentiality boundaries. Concurrently, the manipulation of the vulnerable component triggers resource exhaustion or application instability, culminating in a partial denial of service (partial DOS) that degrades availability for legitimate users of the affected service."
}
CVE-2026-70853: Oracle Hyperion Financial Management Security Vulnerability (LOW Severity, CVSS: 3.3) - Sceawere