Executive brief
Oracle Hyperion Financial Management is a financial planning and management system used by enterprises to consolidate and analyze financial data. A vulnerability in the Security component allows a low-privileged authenticated attacker to gain full control over the system, potentially compromising all financial data and operations.
Technical details
This is a privilege escalation vulnerability in the Security component of Oracle Hyperion Financial Management. The vulnerability is difficult to exploit and requires network access via HTTP and low-level user privileges, but no user interaction is needed. A successful attack enables complete compromise of the system (confidentiality, integrity, and availability impacts). The attack vector is network-based with the precondition that the attacker has low-privileged authentication credentials. No patch information is available in the provided advisory.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed