Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 3.0 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L).
Published: 2026-08-18
Score: 3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in Oracle Hyperion Financial Management version 11.2.25.0.000 allows a high‑privileged local attacker who can log on to the underlying infrastructure to compromise the application. The flaw permits unauthorized update, insert, or delete operations against data that the attacker is not authorized to handle and can also trigger a partial denial of service. The weakness is an improper access control flaw that permits escalation of privileges within the application, resulting in integrity and availability impacts as reflected by the CVSS base score of 3.0.

Affected Systems

Oracle Hyperion Financial Management version 11.2.25.0.000 from Oracle Corporation is affected. No additional versions or product variants are listed.

Risk and Exploitability

The CVSS score of 3.0 indicates low overall severity, and the EPSS score is not available, suggesting that widespread exploitation is currently unlikely. The vulnerability requires local high‑privileged access, limiting the attack surface. It is not listed in the CISA KEV catalog, indicating that advanced persistent threat activity targeting this bug has not been observed. The primary attack vector is local, through credentials or compromised accounts with administrative rights on the host running the application, making containment measures such as restricting who can log into the underlying infrastructure critical.

Generated by OpenCVE AI on August 19, 2026 at 13:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued security patch for Oracle Hyperion Financial Management version 11.2.25.0.000.
  • Restrict local administrative access to the infrastructure hosting Oracle Hyperion Financial Management, ensuring that only trusted personnel can log in.
  • Enable application‑level logging and monitor for unauthorized data modification or partial service interruptions to detect potential exploitation early.

Generated by OpenCVE AI on August 19, 2026 at 13:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title Local Privileged Attacker Can Manipulate Data and Cause Partial DoS in Oracle Hyperion Financial Management

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Local Privileged Attacker Can Manipulate Data and Cause Partial DoS in Oracle Hyperion Financial Management
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 3.0 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:11.340Z

Reserved: 2026-08-04T22:06:34.601Z

Link: CVE-2026-70850

cve-icon Vulnrichment

Updated: 2026-08-19T12:10:52.795Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:40.957

Modified: 2026-08-21T15:23:23.517

Link: CVE-2026-70850

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T13:45:02Z

Weaknesses