Sceawere
Vulnerability Detail
CVE-2026-71146UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Management Denial of Service
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 1.9
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Management
- Attack Type
- Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management.
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 1.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "1.9",
"pubDate": "2026-08-18T21:18:15.590Z",
"pubdate": "2026-08-18T21:18:15.590Z",
"executiveSummary": "An elevation of privilege and denial of service vulnerability exists within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. This security flaw allows a highly privileged attacker who has successfully obtained local logon access to the underlying infrastructure executing the application to compromise the stability of Oracle Hyperion Financial Management. Successful exploitation of this vulnerability requires high privileges and difficult attack conditions, limiting the scope of the compromise exclusively to availability impacts. The primary consequence of a successful attack is the unauthorized capability to trigger a partial denial of service against the affected application, degrading operational availability. The Common Vulnerability Scoring System version 3.1 assigns a base score of 1.9, reflecting the restricted attack vector and high prerequisite privilege levels required for successful exploitation.",
"technicalDetails": "The vulnerability resides within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The root cause stems from insufficient validation or improper resource management within security handling routines executed locally on the host infrastructure. Exploitation of this vulnerability is characterized by a low attack vector (AV:L), meaning the adversary must execute the attack locally on the infrastructure where Oracle Hyperion Financial Management executes, as remote network exploitation is not feasible. The attack complexity is rated as high (AC:H), requiring specific, non-standard execution conditions or race conditions to be met by the threat actor. Furthermore, the vulnerability mandates high privileges (PR:H), dictating that the attacker must already possess administrative or equivalent high-level authorization within the local execution environment prior to initiating the attack sequence. User interaction is not required (UI:N), and the scope remains unchanged (S:U). The attack flow begins with the authenticated adversary establishing a local session on the target infrastructure with elevated privileges. The attacker then interacts directly with the vulnerable Security component of Oracle Hyperion Financial Management, supplying crafted inputs or manipulating local state parameters that bypass internal checks or exhaust specific software resources. This interaction leads to an anomalous state within the application's security subsystem. Consequently, the payload behavior manifests as a targeted disruption of service processes, resulting in a partial denial of service (A:L) that impairs the operational capacity of the application. The confidentiality (C:N) and integrity (I:N) vectors are entirely unaffected, confirming that the vulnerability is strictly confined to availability degradation without data exfiltration or unauthorized modification risks."
}