Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation solution used by enterprises to manage accounting data and reporting. A vulnerability in its security component allows a high-privileged attacker with local system access to read, modify, or delete sensitive financial data. The impact is limited to local attacks by privileged users and does not affect data availability.
Technical details
This is a local privilege escalation or unauthorized access vulnerability in the security component of Oracle Hyperion Financial Management 11.2.25.0.000. The vulnerability requires a high-privileged attacker with local logon access to the server infrastructure and involves complex exploitation conditions (difficult to exploit, high complexity attack chain). A successful exploit allows unauthorized read, update, insert, or delete operations on financial management data. The vulnerability has a CVSS 3.1 base score of 3.0 with low confidentiality and integrity impacts and no availability impact (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N).
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed