Executive brief
Oracle Hyperion Financial Management is an enterprise financial planning and consolidation system used by organizations to manage budgets and financial reporting. An unauthenticated attacker can exploit this vulnerability over the network to crash the application repeatedly or cause it to stop responding, resulting in service outages that prevent financial staff from accessing critical planning and reporting functions.
Technical details
This is a denial-of-service vulnerability in Oracle Hyperion Financial Management's security component affecting version 11.2.26.0.000. The vulnerability is easily exploitable and requires no authentication, with the attack vector being HTTP network traffic. An unauthenticated attacker with network access can send specially crafted HTTP requests to trigger a hang or crash condition, causing a complete denial of service. The flaw impacts only availability; no confidentiality or integrity compromise is possible.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed