Executive brief
Oracle Hyperion Financial Management is a widely-used financial planning and consolidation system. A high-privilege local vulnerability allows an authenticated administrator on the server to escalate privileges and take over the application, potentially affecting other systems in the environment. The vulnerability requires elevated access and difficult exploitation conditions, but successful exploitation could result in complete application compromise and exposure of sensitive financial data.
Technical details
The vulnerability exists in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. It is a local privilege escalation flaw that requires high-level privileges and logon to the infrastructure where the application runs; network exploitation is not possible. The vulnerability has a scope change impact, meaning that while the flaw resides in Hyperion Financial Management, successful exploitation can affect additional connected systems. An attacker with high-level local access can achieve complete compromise (confidentiality, integrity, and availability impacts), resulting in takeover of the application. Patches or mitigations are available from Oracle.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed