Sceawere

Vulnerability Detail

CVE-2026-70870UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Web Client Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Data Relationship Management
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Data Relationship Management.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Web Client - Unicode). The supported version that is affected is 11.2.23.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-08-18T21:17:43.240Z",
  "pubdate": "2026-08-18T21:17:43.240Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Web Client - Unicode component of Oracle Hyperion Data Relationship Management version 11.2.23.0.000. This security flaw allows unauthenticated threat actors leveraging network access via the HTTP protocol to compromise the affected application.\nSuccessful exploitation of this vulnerability results in severe security implications, specifically granting unauthorized access to critical data or complete access to all data accessible within Oracle Hyperion Data Relationship Management, alongside the capability to induce a partial denial of service condition against the target system.\nThe vulnerability carries a CVSS 3.1 Base Score of 8.2 with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L, highlighting high confidentiality impacts and low availability impacts.\nAttackers require no privileges or user interaction to mount an attack, relying solely on network connectivity over HTTP to interact directly with the vulnerable Web Client - Unicode component. The high severity underscores the risk of unauthorized data exposure and service degradation for organizations operating the impacted Oracle Hyperion Data Relationship Management deployment.",
  "technicalDetails": "The vulnerability resides in the Web Client - Unicode component of Oracle Hyperion Data Relationship Management version 11.2.23.0.000. Specifically, the flaw stems from insecure handling of Unicode input processed by the web client interface, exposing an attack surface accessible via standard network protocols.\nExploitation of this vulnerability is categorized under network vector (AV:N), indicating that attackers do not require local access to the host operating system. The attack complexity is rated as low (AC:L), meaning successful exploitation does not demand specialized conditions or complex bypass mechanisms. Furthermore, the vulnerability requires zero privileges (PR:N) and no user interaction (UI:N), allowing unauthenticated remote entities to interact directly with the vulnerable endpoints.\nThe attack flow proceeds as follows: an unauthenticated attacker crafts a specialized HTTP request containing malicious Unicode payloads targeting the vulnerable Web Client - Unicode component. Upon receipt, the application fails to properly sanitize, validate, or parse the input data securely. This improper input handling triggers an internal application error or logic flaw.\nRegarding payload behavior and post-exploitation impact, the successful processing of the malicious HTTP request yields severe confidentiality and availability consequences. For confidentiality (C:H), the attacker gains unauthorized read access to critical data repositories or complete access to all data accessible within the Oracle Hyperion Data Relationship Management instance, potentially exposing sensitive master data management records. For availability (A:L), the flaw permits the attacker to disrupt application operations, resulting in a partial denial of service that degrades system responsiveness or functionality. The scope remains unchanged (S:U), as the impact is confined to the vulnerable Oracle Hyperion Data Relationship Management component itself without directly compromising underlying host hypervisor or core operating system resources."
}
CVE-2026-70870: Oracle Hyperion Web Client Vulnerability (HIGH Severity, CVSS: 8.2) - Sceawere