Sceawere

Vulnerability Detail

CVE-2026-70938UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Management Access Control Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Management
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-18T21:17:51.890Z",
  "pubdate": "2026-08-18T21:17:51.890Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. This security flaw enables a network-based attacker with low privileges to compromise the confidentiality of the application.\nThe vulnerability manifests through unauthorized data access capabilities over the HTTP protocol, requiring no user interaction for successful exploitation. An adversary leveraging this security weakness can achieve unauthorized access to critical data or obtain complete access to all data accessible within Oracle Hyperion Financial Management.\nGiven the CVSS 3.1 Base Score of 6.5 with a vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, the risk implications are concentrated heavily on confidentiality impacts while integrity and availability remain unaffected.\nThe attack vector is network-based with low attack complexity, requiring authenticated low-privileged access to initiate exploitation. Organizations utilizing the affected version face significant exposure regarding sensitive financial and corporate data housed within the Hyperion platform.",
  "technicalDetails": "The vulnerability resides in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000, specifically impacting access control enforcement mechanisms.\nThe root cause stems from insufficient authorization checks within the application logic governing data access requests handled via the HTTP protocol.\nExploitation requires the attacker to possess low-privileged network access to the target system. Because the attack complexity is rated as low, an adversary can reliably interact with the vulnerable HTTP endpoints without encountering significant barriers or specialized environmental dependencies.\nThe attack flow proceeds as follows: First, the authenticated low-privileged attacker establishes a network connection to the Oracle Hyperion Financial Management instance over HTTP. Second, the attacker crafts and transmits malicious or unauthorized requests targeted at the Security component or associated data retrieval interfaces. Third, due to the inadequate validation of privileges and access boundaries within the vulnerable component, the application fails to reject the unauthorized query. Finally, the server processes the request and returns the sensitive data to the attacker, bypassing intended isolation boundaries.\nThe payload behavior focuses entirely on data exfiltration and unauthorized information disclosure, aligning with the CVSS metric of high confidentiality impact (C:H).\nPost-exploitation impact includes the exposure of critical financial records, proprietary corporate information, and any other restricted datasets accessible to the broader Oracle Hyperion Financial Management application.\nNo user interaction is required (UI:N) and the scope remains unchanged (S:U), indicating that the compromise is contained within the application's authorization boundary but effectively breaches all intended logical segmentation between user privilege tiers."
}
CVE-2026-70938: Oracle Hyperion Financial Management Access Control Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere