Sceawere
Vulnerability Detail
CVE-2026-70934UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Management Security Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Management
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-08-18T21:17:51.443Z",
"pubdate": "2026-08-18T21:17:51.443Z",
"executiveSummary": "An easily exploitable vulnerability exists within the Security component of the Oracle Hyperion Financial Management product, specifically affecting version 11.2.25.0.000. This security flaw permits a low-privileged remote attacker with network access via the HTTP protocol to compromise the affected software, leading to significant confidentiality and availability impacts.\nSuccessful exploitation of this vulnerability grants the adversary unauthorized access to critical data or complete access to all data accessible within Oracle Hyperion Financial Management, while also enabling an unauthorized capability to induce a partial denial of service (partial DOS) condition against the application.\nThe vulnerability carries a CVSS 3.1 Base Score of 7.1 with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L. The attack vector is network-based (AV:N), attack complexity is low (AC:L), privileges required are low (PR:L), user interaction is not required (UI:N), scope is unchanged (S:U), confidentiality impact is high (C:H), integrity impact is none (I:N), and availability impact is low (A:L).\nRisk implications include severe data exposure of sensitive financial information and operational disruption via partial denial of service. Remediation requires applying the official vendor-supplied updates or patches corresponding to the affected version.",
"technicalDetails": "The vulnerability resides in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The root cause stems from insufficient access controls, authorization enforcement, or input validation mechanisms within the security handling routines accessible via the application's HTTP interface.\nTo execute an attack, the adversary must possess network access to the target system utilizing the HTTP protocol. Additionally, the attacker must have authenticated access to the application with low privileges, meaning valid user credentials are required to initiate the attack vector.\nThe attack flow proceeds as follows: First, the low-privileged attacker establishes an HTTP connection to the vulnerable Oracle Hyperion Financial Management application endpoint. Second, the attacker submits crafted requests targeting the Security component. Because the component fails to properly validate the authorization boundaries or handles requests insecurely, the application processes the request beyond the attacker's authorized privilege level.\nPost-exploitation impact manifests in two primary ways regarding the CVSS metric dimensions. For confidentiality, the attacker bypasses security controls to read critical and restricted data, resulting in a high confidentiality impact (C:H) where all Oracle Hyperion Financial Management accessible data may be compromised. For availability, the malicious manipulation of the security component induces resource exhaustion or service degradation, resulting in a partial denial of service (A:L). Integrity remains unaffected as denoted by the none rating (I:N).\nThe exploitation method relies entirely on network-based HTTP traffic, requiring low attack complexity (AC:L) and no user interaction (UI:N). The scope remains unchanged (S:U) as the vulnerability impacts resources strictly within the security context of the vulnerable component itself without crossing security spheres."
}