Executive brief
Oracle Hyperion Financial Management is a financial planning and analysis platform used by enterprises for budgeting and forecasting. An unauthenticated attacker can exploit this vulnerability through HTTP to perform unauthorized data operations (read, insert, update, or delete) if a user clicks a malicious link while logged in to the system. Successful exploitation could lead to unauthorized access to financial data and undetected fraudulent changes to records.
Technical details
This is a cross-site request forgery (CSRF) vulnerability in Oracle Hyperion Financial Management's security component. The vulnerability is easily exploitable and requires network access via HTTP, with no authentication needed from the attacker; however, it requires user interaction (the victim must click a link or visit a malicious page while authenticated). An unauthenticated attacker can craft a request that executes with the privileges of an authenticated user, resulting in unauthorized read access to a subset of accessible data and unauthorized update, insert, or delete operations. The affected version is 11.2.25.0.000. Patch status and mitigation details are not available from the provided advisory text.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed