Executive brief
Oracle Hyperion Financial Management is a financial consolidation and planning application used by enterprises to manage consolidated financial results and close processes. A vulnerability in its security component allows a local attacker with low-level access to manipulate critical financial data without proper authorization, requiring user interaction from another party. Successful exploitation could result in unauthorized creation, deletion, or modification of financial records with impacts across dependent systems.
Technical details
This is a privilege escalation vulnerability in the security component of Oracle Hyperion Financial Management (version 11.2.25.0.000). The vulnerability requires an attacker to have local logon access to the infrastructure and requires user interaction from a different user, making it difficult to exploit. The attack vector is local (AV:L) with high complexity (AC:H) and low privilege requirements (PR:L). Successful exploitation allows an attacker to bypass integrity controls and create, delete, or modify critical data within the application, with potential scope change affecting additional products. No patch status or workarounds are explicitly mentioned in the advisory.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed