Sceawere

Vulnerability Detail

CVE-2026-70975UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Management Access Control Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Management
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-18T21:17:56.223Z",
  "pubdate": "2026-08-18T21:17:56.223Z",
  "executiveSummary": "An easily exploitable security vulnerability affects the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. This vulnerability permits a low-privileged remote attacker with network access via HTTP to compromise the confidentiality of the target application.\nSuccessful exploitation of this flaw results in unauthorized access to critical data or complete exposure of all data accessible within Oracle Hyperion Financial Management. The vulnerability carries a CVSS 3.1 Base Score of 6.5, with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, indicating that integrity and availability impacts are none, while confidentiality impact is high.\nThe attack vector is network-based (AV:N), requiring low attack complexity (AC:L), low privileges (PR:L), and no user interaction (UI:N). The scope remains unchanged (S:U). Organizations utilizing the affected version face significant risk of data exposure regarding sensitive financial information managed within the application.",
  "technicalDetails": "The vulnerability resides within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The underlying root cause involves improper access control enforcement within the application's authorization framework, allowing authenticated users with minimal privileges to bypass intended security boundaries and access sensitive data assets they are not authorized to view.\nExploitation of this vulnerability requires network connectivity to the target system via the HTTP protocol. The attacker must possess low privileges, meaning an authenticated user account with standard or restricted access rights is required to initiate the attack. No user interaction or complex preconditions are necessary, as denoted by the low attack complexity metric.\nThe attack flow proceeds as follows: First, the attacker establishes network connectivity to the vulnerable Oracle Hyperion Financial Management instance over HTTP. Second, the attacker authenticates using their low-privileged credentials to obtain a valid session or authorization token. Third, the attacker crafts malicious or out-of-scope HTTP requests directed at the Security component or associated data endpoints, deliberately omitting or manipulating parameter constraints meant to enforce data segregation.\nBecause the Security component fails to properly validate the user's authorization level against the requested resource, the server processes the request and returns the sensitive data. Post-exploitation impact is strictly confined to confidentiality, enabling the adversary to harvest critical financial data or achieve complete unauthorized visibility over all data repositories accessible by the Oracle Hyperion Financial Management application."
}
CVE-2026-70975: Oracle Hyperion Financial Management Access Control Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere