Executive brief
Oracle Hyperion Financial Management is a financial consolidation and reporting platform used by enterprises to manage accounting and budgeting processes. A network-accessible vulnerability in the security component allows unauthenticated attackers to read, insert, update, or delete sensitive financial data without proper authorization, potentially exposing confidential financial information and enabling unauthorized modifications to accounting records.
Technical details
This is a difficult-to-exploit authentication bypass or authorization flaw in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The vulnerability is reachable over HTTP via network access without requiring authentication. An unauthenticated attacker can exploit this to gain unauthorized access to read a subset of accessible data and modify (insert, update, delete) some protected data. The attack requires specific network conditions (CVSS AC:H), but no user interaction is needed. Patches are expected from Oracle; users should monitor security advisories for fixes.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed