Executive brief
Oracle Hyperion Financial Management is a financial consolidation and planning platform used by enterprises to manage budgeting and reporting. This vulnerability allows a low-privileged user with local access to the server to gain unauthorized read and write access to sensitive financial data and temporarily disrupt the system, provided they can trick another user into performing an action. The impact includes data theft, unauthorized modification of financial records, and service disruption.
Technical details
This is a privilege escalation vulnerability in the Security component of Oracle Hyperion Financial Management 11.2.25.0.000. The flaw requires local access to the infrastructure where the application is deployed and a low privilege account, combined with social engineering or user interaction from a different user to trigger the exploit. An attacker can achieve unauthorized read access to a subset of accessible data, unauthorized modification (update/insert/delete) of data, and cause a partial denial of service. The vulnerability is difficult to exploit due to the requirements for local access and user interaction. Patch availability is not explicitly mentioned in the advisory.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed