Executive brief
Oracle Hyperion Financial Management is a financial consolidation and reporting system used by enterprises to manage and analyze financial data. A vulnerability in the product's security component allows an authenticated local attacker to modify financial data (insert, update, or delete records) without proper authorization, requiring user interaction to exploit. This could lead to unauthorized changes to financial records and potential compliance violations.
Technical details
The vulnerability is a privilege escalation flaw in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. It requires local access to the infrastructure where the product executes (AV:L), a high complexity attack (AC:H), no special privileges (PR:N), and user interaction (UI:R) to exploit. An unauthenticated attacker with local logon access can achieve unauthorized update, insert, or delete access to Oracle Hyperion Financial Management data. The vulnerability does not provide confidentiality or availability impacts, only integrity impacts. No patch information is currently available in the advisory.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed: Published in Oracle Security Alert