Executive brief
Oracle Hyperion Financial Management is an enterprise application used for financial planning and consolidation. A vulnerability in the security component allows a high-privilege attacker with network access to expose critical financial data or completely disable the system, impacting both confidentiality and availability of financial operations.
Technical details
An easily exploitable vulnerability exists in the security component of Oracle Hyperion Financial Management 11.2.25.0.000. The vulnerability is remotely accessible via HTTP and requires high-level administrative privileges to exploit. Successful exploitation can lead to unauthorized access to sensitive financial data and denial of service through system hangs or crashes. The CVSS 3.1 vector (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H) reflects network accessibility, low attack complexity, and high-privilege requirement, with significant impacts on confidentiality and availability but not integrity.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed