Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-08-18
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Security component of Oracle Hyperion Financial Management. It permits a low‑privileged attacker with network access over HTTP to perform unauthorized updates, inserts, deletes or reads on a subset of the application’s data, and to induce a partial denial of service. The flaw results from insufficient access control checks, identified as CWE‑284, and has a CVSS v3.1 base score of 6.3 reflecting moderate severity with impacts on confidentiality, integrity and availability.

Affected Systems

Affected systems are Oracle Hyperion Financial Management releases version 11.2.25.0.000, which is explicitly listed as vulnerable in Oracle’s August 2026 CSPU security bulletin.

Risk and Exploitability

The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L) indicates a network attack requiring only low privilege. The EPSS score is < 1 %, indicating a very low but nonzero probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker does not need elevated or local administrative credentials—low‑privileged accounts are sufficient to exploit the flaw. Attackers would need to craft and send a malicious HTTP request to a vulnerable Hyperion instance.

Generated by OpenCVE AI on August 20, 2026 at 22:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security patch published in the August 2026 CSPU for Oracle Hyperion Financial Management version 11.2.25.0.000.
  • Restrict inbound HTTP traffic to the Hyperion instance to trusted internal networks or VPN endpoints to reduce remote exposure.
  • Enforce strict role‑based access controls on Hyperion objects to prevent unauthorized update, delete or read operations by low‑privileged users.

Generated by OpenCVE AI on August 20, 2026 at 22:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Remote HTTP-Based Unauthorized Data Modification and Partial Denial in Oracle Hyperion Financial Management

Thu, 20 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Remote HTTP-Based Unauthorized Data Modification and Partial Denial in Oracle Hyperion Financial Management

Wed, 19 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial via HTTP in Oracle Hyperion Financial Management

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial via HTTP in Oracle Hyperion Financial Management
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:07.722Z

Reserved: 2026-08-04T22:06:34.617Z

Link: CVE-2026-71103

cve-icon Vulnrichment

Updated: 2026-08-19T12:09:17.658Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:10.607

Modified: 2026-08-20T15:22:43.990

Link: CVE-2026-71103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T23:00:07Z

Weaknesses