Executive brief
Oracle Hyperion Financial Management is a financial consolidation and reporting system used by enterprises to manage budgets, forecasts, and financial data. A SQL injection vulnerability in the Security component allows a low-privileged network attacker to read, modify, or delete sensitive financial data and reports without proper authorization, potentially compromising the integrity and confidentiality of critical business information.
Technical details
The vulnerability is a SQL injection flaw in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. It is easily exploitable and requires network access and low-privilege authentication; no user interaction is needed. An authenticated attacker can inject malicious SQL via the network-accessible SQL interface to execute arbitrary database queries, resulting in unauthorized access, modification, or deletion of financial data. The CVSS 3.1 score is 8.1 (High) with high confidentiality and integrity impacts. Patch status and mitigation guidance should be obtained from Oracle's security advisory.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed