Executive brief
Oracle Hyperion Financial Management is a widely-used enterprise financial planning and consolidation platform. A SQL injection vulnerability in the security component allows a high-privileged attacker with network access to fully compromise the system, potentially leading to unauthorized access to sensitive financial data, manipulation of financial records, and service disruption.
Technical details
A SQL injection vulnerability exists in Oracle Hyperion Financial Management version 11.2.26.0.000 within the security component. The vulnerability is easily exploitable and requires network access and high privileges (authenticated attacker). Successful exploitation allows an attacker to compromise confidentiality, integrity, and availability of the system through SQL injection techniques. The attack vector is network-based with low complexity. Patches or updates for this vulnerability may be available through Oracle's official security advisories.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed