Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-08-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the security component of Oracle Hyperion Financial Management and allows a low-privileged attacker who can reach the system over HTTP to obtain read-only access to critical or all application data. The vulnerability is described as difficult to exploit and provides no direct operating-system compromise; however, it results in a high confidentiality impact while leaving integrity and availability unaffected, as reflected in the CVSS vector.

Affected Systems

Oracle Corporation’s Oracle Hyperion Financial Management version 11.2.25.0.000 is affected. No patch or workaround has been released at the time of this advisory, so protection must focus on behavioral controls until an update is available.

Risk and Exploitability

The CVSS base score of 5.3 classifies the issue as moderate severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, implying no known used exploits. The attack can be carried out from any Internet accessible interface using HTTP and requires the attacker to operate under a low-privilege account, as inferred from the CVSS vector.

Generated by OpenCVE AI on August 24, 2026 at 20:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Oracle patch for version 11.2.25.0.000 once released
  • Restrict HTTP access to Oracle Hyperion Financial Management to trusted IP ranges or a VPN tunnel only
  • Monitor application logs for abnormal data access patterns and block suspicious IP addresses

Generated by OpenCVE AI on August 24, 2026 at 20:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Leading to Unauthorized Data Disclosure in Oracle Hyperion Financial Management

Mon, 24 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Fri, 21 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP-Based Unauthorized Data Access in Oracle Hyperion Financial Management

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP-Based Unauthorized Data Access in Oracle Hyperion Financial Management
Weaknesses CWE-200
CWE-269

Thu, 20 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-269

Wed, 19 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Attack Allows Full Access to Oracle Hyperion Financial Management Data
Weaknesses CWE-200
CWE-269

Wed, 19 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Attack Allows Full Access to Oracle Hyperion Financial Management Data
Weaknesses CWE-200
CWE-269

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T17:59:52.519Z

Reserved: 2026-08-04T22:06:34.617Z

Link: CVE-2026-71108

cve-icon Vulnrichment

Updated: 2026-08-20T17:47:31.546Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:11.167

Modified: 2026-08-24T18:38:19.320

Link: CVE-2026-71108

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:00:13Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control