Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation system used by enterprises to manage budgets, forecasts, and financial reports. A vulnerability in its security component allows a low-privileged attacker with network access to escalate privileges and take full control of the system, potentially compromising all financial data and reporting integrity.
Technical details
This is an easily exploitable vulnerability in the security component of Oracle Hyperion Financial Management 11.2.25.0.000. The flaw allows a low-privileged attacker with network access via TCP to achieve complete system compromise without requiring user interaction. Successful exploitation results in full takeover of the application, enabling attackers to read, modify, or delete sensitive financial data and disable the system. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates low attack complexity and no user interaction required. Patch status and detailed vulnerability class information are not available from the provided advisory.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed