Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation platform used by enterprises to manage budgets and financial data. An unauthenticated attacker can bypass security controls and read sensitive financial data without valid credentials, potentially exposing confidential information to unauthorized parties.
Technical details
The vulnerability is an authentication bypass in Oracle Hyperion Financial Management's security component affecting version 11.2.25.0.000. An unauthenticated attacker can exploit this via HTTP with no special preconditions (network access only), allowing unauthorized read access to a subset of accessible data. The attack requires no user interaction and has a CVSS 3.1 score of 5.3 (confidentiality impact only, no integrity or availability impact). Patches are available from Oracle.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed