Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 4.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L).
Published: 2026-08-18
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Hyperion Financial Management’s security component is vulnerable to unauthenticated attackers who can access the application over HTTP. The flaw enables attackers to insert, update or delete data that requires proper authorization (CWE‑284) and to trigger a partial denial of service, compromising data integrity and reducing application availability. The CVSS v3.1 base score of 4.2 reflects these non‑catastrophic but still significant integrity and availability impacts.

Affected Systems

Only Oracle Hyperion Financial Management version 11.2.25.0.000 is affected; the risk applies to all users who can reach the application on that version.

Risk and Exploitability

The EPSS score of less than 1 % indicates that current evidence of exploitation is extremely low, and the vulnerability is not listed in the CISA KEV catalog. Attackers require network access to the public HTTP interface but no privileges. Importantly, the description states that successful attacks necessitate human interaction by a third party, which makes the exploitation path difficult. Thus, despite the vulnerability’s existence, the likelihood of it being actively exploited in the wild is considered low, though the potential impact should not be underestimated.

Generated by OpenCVE AI on August 20, 2026 at 14:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security patch for version 11.2.25.0.000 as detailed in Oracle’s security alert
  • Restrict HTTP access to Hyperion Financial Management to trusted IP ranges or route traffic through a VPN or firewall
  • Monitor application logs for unauthorized data modification attempts and partial denial of service indicators and investigate anomalies promptly

Generated by OpenCVE AI on August 20, 2026 at 14:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification in Oracle Hyperion Financial Management

Wed, 19 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Modification and Partial Denial of Service via HTTP in Oracle Hyperion Financial Management
Weaknesses CWE-400

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Modification and Partial Denial of Service via HTTP in Oracle Hyperion Financial Management
Weaknesses CWE-284
CWE-400

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 4.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:06.700Z

Reserved: 2026-08-04T22:06:34.620Z

Link: CVE-2026-71147

cve-icon Vulnrichment

Updated: 2026-08-19T12:08:38.031Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:15.710

Modified: 2026-08-20T15:21:55.610

Link: CVE-2026-71147

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T14:45:16Z

Weaknesses