Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 4.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-08-18
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Security component of Oracle Hyperion Financial Management allows a local attacker with low privileges who can log on to the host where the application runs to cause the application to hang or repeatedly crash, resulting in a loss of availability. This weakness is a form of unauthorized access (CWE‑284) that affects only availability, leaving confidentiality and integrity untouched.

Affected Systems

Oracle Hyperion Financial Management 11.2.25.0.000 is the only technical version that is identified as vulnerable in the CVE data. The product is distributed by Oracle Corporation.

Risk and Exploitability

The CVSS 3.1 base score of 4.7 reflects a high impact on availability with local access (AV:L) and low privilege (PR:L). The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating that widespread exploitation is unlikely. Nonetheless, because an adversary who can log on locally can trigger repeated crashes, the overall risk can be considered moderate given the limited exploitation conditions.

Generated by OpenCVE AI on August 24, 2026 at 20:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the official Oracle patch for version 11.2.25.0.000 that fixes the Security component flaw or upgrade to a newer supported release.
  • Limit local login capabilities to trusted accounts and enforce least‑privilege access on the application servers.
  • Implement monitoring and alerting to detect hangs or crashes so that incidents can be investigated promptly.

Generated by OpenCVE AI on August 24, 2026 at 20:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Local Denial‑of‑Service Vulnerability in Oracle Hyperion Financial Management

Mon, 24 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Fri, 21 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Local Denial‑of‑Service Vulnerability in Oracle Hyperion Financial Management

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Local Denial of Service Vulnerability in Oracle Hyperion Financial Management 11.2.25.0.000
Weaknesses CWE-749

Thu, 20 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Local Denial of Service Vulnerability in Oracle Hyperion Financial Management 11.2.25.0.000
Weaknesses CWE-749

Wed, 19 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Denial of Service in Oracle Hyperion Financial Management via Low-Privilege Exploit
Weaknesses CWE-749

Wed, 19 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Title Denial of Service in Oracle Hyperion Financial Management via Low-Privilege Exploit
Weaknesses CWE-749

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 4.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T18:00:10.586Z

Reserved: 2026-08-04T22:06:34.617Z

Link: CVE-2026-71105

cve-icon Vulnrichment

Updated: 2026-08-20T17:47:29.475Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:10.827

Modified: 2026-08-24T18:38:21.913

Link: CVE-2026-71105

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:00:13Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control