Sceawere
Vulnerability Detail
CVE-2026-71148UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Management Information Disclosure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Management
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-08-18T21:18:15.823Z",
"pubdate": "2026-08-18T21:18:15.823Z",
"executiveSummary": "An unauthenticated information disclosure vulnerability affects the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. This security flaw allows remote attackers with network access via HTTP to bypass authorization controls and compromise the confidentiality of the application. Successful exploitation results in unauthorized read access to a specific subset of sensitive data stored within or accessible by Oracle Hyperion Financial Management. The vulnerability carries a CVSS 3.1 Base Score of 5.3 with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, indicating that exploitation requires low complexity, no prior authentication, and no user interaction, while impacting exclusively confidentiality. Risk implications include the potential exposure of proprietary financial data, internal system structures, or user information to unauthorized external parties. Organizations utilizing the affected software version must implement appropriate defensive measures to mitigate potential unauthorized data extraction over the network.",
"technicalDetails": "The vulnerability resides within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The root cause stems from improper access control enforcement within the application request handling logic, specifically regarding endpoints exposed over the HTTP protocol. Because the affected component fails to adequately validate the authorization status of incoming requests, unauthenticated remote attackers can directly interact with vulnerable interfaces.\nExploitation is conducted via the network vector (AV:N), requiring only standard HTTP connectivity to the target application server. The attack complexity is rated as low (AC:L) because no specialized conditions, race conditions, or complex exploitation primitives are required to induce the failure state. Furthermore, the vulnerability requires no privileges (PR:N) and no user interaction (UI:N), allowing automated scripts or remote adversaries to initiate malicious requests directly against the exposed HTTP service.\nDuring a typical attack flow, an unauthenticated adversary crafts a malicious HTTP request targeted at the vulnerable Security component of Oracle Hyperion Financial Management. Upon receipt of the request, the application processes the input without properly verifying whether the originating session possesses the necessary authorization rights to access the requested resource. Consequently, the server improperly discloses restricted information back to the client in the HTTP response payload.\nThe post-exploitation impact is strictly confined to confidentiality (C:L), resulting in unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. The vulnerability does not provide integrity (I:N) or availability (A:N) impact, meaning attackers cannot modify data, execute arbitrary code, or cause denial of service conditions through this specific vector. The scope remains unchanged (S:U), restricting the compromise to the application context itself without directly escalating to underlying operating system resources."
}