Sceawere
Vulnerability Detail
CVE-2026-71145UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Management Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.4
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Management
- Attack Type
- Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.4",
"pubDate": "2026-08-18T21:18:15.480Z",
"pubdate": "2026-08-18T21:18:15.480Z",
"executiveSummary": "A vulnerability exists within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000, allowing network-based exploitation via HTTP. This security flaw is categorized as difficult to exploit and requires low-privileged attacker access alongside victim human interaction.\nSuccessful exploitation of this vulnerability results in a scope change, potentially impacting additional products beyond the primary vulnerable system. The impact is limited to unauthorized read, update, insert, or delete access to a subset of data accessible within Oracle Hyperion Financial Management, while availability remains unaffected.\nThe risk profile indicates that an authenticated low-privileged user leveraging network vectors can manipulate application logic or data flows, provided a third party interacts with the crafted attack mechanism. Organizations utilizing the affected Oracle Hyperion Financial Management version must evaluate network exposure and monitor unauthorized data access patterns.",
"technicalDetails": "The vulnerability resides in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. It is exposed via the HTTP network attack vector, requiring the attacker to possess low privileges within the application context.\nExploitation complexity is classified as high, indicating that successful execution depends on specific conditions, precise timing, or non-default configurations. Furthermore, the attack vector mandates user interaction from a distinct individual other than the attacker, typically manifesting as social engineering or induced victim navigation to a malicious resource.\nThe attack flow proceeds as follows: First, the low-privileged attacker crafts an HTTP request targeting the Security component of Oracle Hyperion Financial Management. Second, the attacker induces human interaction, requiring a targeted user to execute an action within the application context while the malicious payload is processed. Third, due to insufficient input validation, authorization enforcement, or handling within the Security component, the system processes the request under conditions that trigger a scope change (S:C).\nThis scope change allows the exploitation context to transcend the boundary of Oracle Hyperion Financial Management, potentially impacting secondary or integrated products connected to the deployment. Upon successful execution, the attack yields partial confidentiality and integrity impacts. Specifically, the adversary gains unauthorized read access to a subset of accessible data, as well as unauthorized update, insert, or delete capabilities against specific data repositories within the application scope. Availability (A) impact is rated as none, meaning the service remains operational and does not experience denial-of-service conditions during the attack.\nThe CVSS 3.1 vector string is (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N), which translates to a Base Score of 4.4. This underscores that while network exposure and low privileges are prerequisites, the high attack complexity and necessity of user interaction mitigate the immediate severity, though cross-component scope implications require careful defensive oversight."
}