Executive brief
Oracle Hyperion Financial Management is a critical enterprise financial planning and analysis platform used by organizations to manage budgets, forecasts, and consolidated financial data. An unauthenticated attacker can exploit a network-accessible vulnerability to modify or delete financial data, disrupt service availability, and potentially cause complete system outages, directly threatening data integrity and business operations.
Technical details
This vulnerability in the Security component of Oracle Hyperion Financial Management 11.2.25.0.000 allows unauthenticated remote attackers to bypass authentication via HTTP without any user interaction or complex exploitation steps. The vulnerability enables unauthorized data manipulation (creation, deletion, modification), data disclosure, and denial-of-service attacks against the application. The attack requires only network access to the affected system and no authentication credentials. A fix or patch availability has not been confirmed at this time.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed