Sceawere

Vulnerability Detail

CVE-2026-71147UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Management Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.2
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Management
Attack Type
Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management.
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 4.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.2",
  "pubDate": "2026-08-18T21:18:15.710Z",
  "pubdate": "2026-08-18T21:18:15.710Z",
  "executiveSummary": "A security vulnerability has been identified within the Security component of the Oracle Hyperion Financial Management product, specifically affecting version 11.2.25.0.000. This vulnerability exposes enterprise deployments to security risks via remote network vectors.\nThe vulnerability allows an unauthenticated attacker leveraging HTTP network access to compromise the application. Successful exploitation of this flaw is classified as difficult to exploit and requires human interaction from a user other than the attacker.\nUpon successful exploitation, the vulnerability impacts both data integrity and system availability. Attackers can gain unauthorized update, insert, or delete access to specific data accessible within Oracle Hyperion Financial Management, as well as cause a partial denial of service condition affecting the application.\nThe severity of this vulnerability is captured by a CVSS 3.1 Base Score of 4.2, with a vector string of CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L, indicating that confidentiality is not impacted, but integrity and availability suffer partial degradation under specific preconditions.",
  "technicalDetails": "The vulnerability resides in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The attack surface is exposed over the network utilizing the HTTP protocol, permitting unauthenticated remote entities to interact with vulnerable endpoints.\nExploitation requires specific preconditions, notably a high attack complexity and mandatory human interaction from a third party, such as a targeted user visiting a maliciously crafted link or interacting with a manipulated web interface.\nThe step-by-step attack flow typically involves the attacker crafting a malicious HTTP request targeting the Security component of Oracle Hyperion Financial Management. Because the attacker lacks pre-existing authentication or privileges, they rely on social engineering or user-assisted interaction to trick an authenticated or targeted user into executing the request within their browser session.\nOnce the interaction occurs, the payload exploits processing flaws within the Security component. This bypasses intended input validation or access control mechanisms, allowing the execution of unauthorized data modification operations.\nThe post-exploitation impact is localized to the integrity and availability of the application. Attackers achieve unauthorized insert, update, or delete capabilities against vulnerable data sets within Oracle Hyperion Financial Management, corrupting database records or operational states. Additionally, the payload can trigger resource exhaustion or application instability, culminating in a partial denial of service (partial DoS) condition that degrades operational availability."
}
CVE-2026-71147: Oracle Hyperion Financial Management Vulnerability (MEDIUM Severity, CVSS: 4.2) - Sceawere