Sceawere
Vulnerability Detail
CVE-2026-70935UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Management Access Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Management
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-08-18T21:17:51.550Z",
"pubdate": "2026-08-18T21:17:51.550Z",
"executiveSummary": "An easily exploitable vulnerability exists within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. This security flaw allows a remote, low-privileged attacker with network access via the HTTP protocol to compromise the affected product. Successful exploitation of this vulnerability yields severe confidentiality and availability impacts, resulting in unauthorized access to critical data or complete access to all accessible data within Oracle Hyperion Financial Management, as well as the capability to induce a partial denial of service condition. The severity of this issue is reflected by a CVSS 3.1 Base Score of 7.1 with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L. The risk implications include the potential exposure of sensitive financial data and operational disruption of enterprise reporting systems. Exploitation requirements necessitate network connectivity and low-privileged authentication, but do not require user interaction or complex attack conditions.",
"technicalDetails": "The vulnerability resides in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The root cause stems from insufficient access controls and authorization enforcement mechanisms within the application logic handling HTTP requests. Because the network exposure is set to the network layer (AV:N), an attacker can interact directly with the application over HTTP without physical access or local host presence. The attack complexity is rated as low (AC:L), indicating that the targeted component lacks robust safeguards against abuse by authenticated users. To execute an attack, the adversary must possess low privileges (PR:L) within the domain of the application, authenticating via standard HTTP mechanisms. No user interaction (UI:N) is required, meaning the exploit can be executed programmatically and deterministically by the attacker. Upon establishing a valid low-privileged session, the attacker crafts malicious HTTP requests directed at the vulnerable Security component. Due to inadequate validation of authorization boundaries, the application fails to restrict the requesting user from querying or retrieving sensitive operational data. The payload behavior triggers unauthorized data enumeration and retrieval, leading to high confidentiality impacts (C:H) where critical or complete financial datasets are exposed to unauthorized entities. Additionally, crafted requests can overwhelm resource allocation or disrupt dependent sub-components, resulting in a partial denial of service (A:L) that degrades system availability. The integrity impact remains none (I:N), as the primary vector targets data exposure and service degradation rather than unauthorized data modification."
}