Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation system used by enterprises to manage budgets and close books. A vulnerability in its security component allows a low-privileged attacker with local access to cause the application to hang or crash repeatedly, disrupting financial operations and user access to the system.
Technical details
This is a denial-of-service vulnerability in Oracle Hyperion Financial Management's Security component. The vulnerability is difficult to exploit and requires local access (adjacent network or physical presence on the infrastructure) combined with low-privileged logon credentials. The attack vector is local (AV:L) with high attack complexity (AC:H) and low privilege requirements (PR:L). Successful exploitation results in availability impact only—an attacker can cause the application to hang or repeatedly crash, but cannot leak data or modify information. No information on patch availability is provided in the advisory.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed