Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-08-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the security component of Oracle Hyperion Financial Management and allows a low‑privileged attacker with network access on HTTP to cause the application to hang or crash repeatedly. The flaw is considered difficult to exploit; successful exploitation results in a denial of service that completely interrupts availability of the Hyperion instance without affecting confidentiality or integrity.

Affected Systems

Affected systems are Oracle Hyperion Financial Management 11.2.25.0.000. No other versions are mentioned as impacted.

Risk and Exploitability

The CVSS 3.1 score is 5.3 and only the availability metric is impacted. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalogue. Attackers would need network connectivity to the Hyperion HTTP interface and do not require elevated privileges. Because the exploit requires specific conditions and is not currently widely observed, the risk is moderate but the impact on business continuity can be significant if the service is critical.

Generated by OpenCVE AI on August 20, 2026 at 17:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued security patch for Hyperion 11.2.25.0.000, which addresses both the improper access control and resource exhaustion weaknesses.
  • Restrict HTTP access to the Hyperion service to trusted hosts or internal networks using firewall rules.
  • Enable or configure rate‑limiting and monitoring on the Hyperion web interface to detect abnormal request patterns.

Generated by OpenCVE AI on August 20, 2026 at 17:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Resource Exhaustion in Oracle Hyperion Financial Management

Wed, 19 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Resource Exhaustion in Oracle Hyperion Financial Management

Wed, 19 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Denial of Service Vulnerability in Oracle Hyperion Financial Management via HTTP
Weaknesses CWE-770

Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Denial of Service Vulnerability in Oracle Hyperion Financial Management via HTTP
Weaknesses CWE-770

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:00:23.368Z

Reserved: 2026-08-04T22:06:34.618Z

Link: CVE-2026-71120

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:12.713

Modified: 2026-08-24T18:11:13.277

Link: CVE-2026-71120

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:00:03Z

Weaknesses