Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).
Published: 2026-08-18
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Hyperion Financial Management contains a security flaw that can be triggered by a low‑privilege attacker with HTTP access. The flaw can be leveraged to cause a partial denial of service, limiting the availability of financial reporting functions. The CVSS base score of 3.1 reflects the limited impact, but the weakness remains exploitable.

Affected Systems

Oracle Corporation’s Hyperion Financial Management version 11.2.25.0.000.

Risk and Exploitability

While the CVSS score is low, the EPSS score of <1% indicates a very low probability of exploitation but not zero. The vulnerability is not listed in CISA KEV, suggesting no known active exploitation. The likely attack vector involves an attacker on the network targeting the Hyperion application over HTTP with low privileges. The risk is focused on availability, potentially disrupting financial reporting for users who rely on the product.

Generated by OpenCVE AI on August 21, 2026 at 04:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Consult Oracle’s security alert and install the issued patch or upgrade to a version newer than 11.2.25.0.000.
  • Restrict HTTP access to the Hyperion Financial Management instance by using firewalls or network segmentation, allowing only authorized personnel to reach the application.
  • Enable detailed logging for the Hyperion application and monitor for repeated error states or resource exhaustion patterns, configuring alerts for potential denial‑of‑service activity.

Generated by OpenCVE AI on August 21, 2026 at 04:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Partial Denial of Service in Oracle Hyperion Financial Management via Low-Privilege HTTP

Wed, 19 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title Oracle Hyperion Financial Management Partial Denial of Service Vulnerability
Weaknesses CWE-699
CWE-770

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Oracle Hyperion Financial Management Partial Denial of Service Vulnerability
Weaknesses CWE-699
CWE-770

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:11.170Z

Reserved: 2026-08-04T22:06:34.601Z

Link: CVE-2026-70851

cve-icon Vulnrichment

Updated: 2026-08-19T12:10:44.710Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:41.087

Modified: 2026-08-21T15:18:45.397

Link: CVE-2026-70851

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T04:45:03Z

Weaknesses