Sceawere
Vulnerability Detail
CVE-2026-70912UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Management Integrity Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Management
- Attack Type
- Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data.
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-08-18T21:17:49.107Z",
"pubdate": "2026-08-18T21:17:49.107Z",
"executiveSummary": "An integrity vulnerability affecting the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000 has been identified. This vulnerability carries a CVSS 3.1 Base Score of 5.3, specifically impacting data integrity with no direct confidentiality or availability disruption.\nThe flaw is classified as difficult to exploit, requiring low-privileged attacker access to the underlying infrastructure where Oracle Hyperion Financial Management executes, alongside mandatory human interaction from a user other than the attacker. Despite these prerequisites, a successful exploit exhibits a scope change, allowing the impact to extend significantly beyond the primary vulnerable component to affect additional integrated products.\nThe primary risk implication of this vulnerability is the potential for unauthorized creation, deletion, or modification of critical data, as well as any other data accessible to Oracle Hyperion Financial Management. Threat actors must possess local access and rely on social engineering or user assistance to trigger the attack flow, making environmental isolation and strict infrastructure access controls critical defense layers against potential exploitation.",
"technicalDetails": "The vulnerability resides within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. According to the CVSS 3.1 vector (AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N), the attack vector is local (AV:L), meaning the adversary must already possess execution capabilities or logon access to the host infrastructure hosting the target application. The attack complexity is rated as high (AC:H), indicating that successful exploitation relies on specific race conditions, complex state manipulations, or non-standard configurations.\nPrivilege requirements are set to low (PR:L), necessitating authenticated local access with standard user rights rather than administrative privileges. Furthermore, the vulnerability mandates user interaction (UI:R), meaning an attacker cannot execute the attack autonomously; it requires a secondary user to perform an action or interact with the compromised interface or localized attack vector. The scope change metric (S:C) is critical, demonstrating that successful exploitation breaks security boundaries, allowing the adversary to impact resources and products outside the direct context of Oracle Hyperion Financial Management.\nThe step-by-step attack flow begins with the low-privileged attacker establishing an authenticated logon session to the infrastructure hosting Oracle Hyperion Financial Management. Due to the high attack complexity and requirement for user interaction, the attacker must manipulate local system states, insecure file permissions, or shared resources, and subsequently induce another user to perform an interactive operation. This interaction triggers the vulnerable Security component handling within Oracle Hyperion Financial Management.\nUpon successful execution of the attack chain, the payload bypasses standard integrity checks enforced by the application's security controls. Because of the scope change attribute, the resulting compromise propagates beyond the local component, granting the adversary unauthorized access capabilities. Consequently, the attacker can execute unauthorized data modifications, payload insertions, or data deletions affecting critical enterprise financial records and any secondary connected products within the administrative domain."
}