cve-2026-71105
MEDIUM CVSS 4.7 opencveVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 4.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
- Published
- 2026-08-18 21:18 UTC
- Last Modified
- 2026-08-24
CVSS details not available.
No product information available.
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 4.7 | MEDIUM | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H |
mitre | ||
| 3.1 | 4.7 | MEDIUM | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H |
nvd | ||
| 3.1 | 4.7 | MEDIUM | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H |
opencve |
No references available.
No linked vulnerabilities found.
{
"cve": "CVE-2026-71105",
"enrichment": {
"affected": [
{
"configurations": [
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "generic",
"value": "11.2.25.0.000"
}
}
],
"enrichment": {
"confidence": 95.0,
"confidence_source": "inferred",
"scores": [
{
"score": 95.0,
"source": "inferred"
},
{
"score": 100.0,
"source": "matching"
}
]
},
"original": {
"product": "Oracle Hyperion Financial Management",
"source": "cna",
"vendor": "Oracle Corporation"
},
"product": "hyperion_financial_management",
"vendor": "oracle"
}
],
"created": "2026-08-19T07:45:17.899976+00:00",
"updated": "2026-08-24T21:00:13.139140+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$hyperion_financial_management"
]
},
"epss": {
"score": 0.00116
},
"mitre": {
"cpes": [
"cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*"
],
"created": "2026-08-18T21:03:32.192000+00:00",
"description": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 4.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 4.7,
"vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2026/71xxx/CVE-2026-71105.json",
"references": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"title": null,
"updated": "2026-08-20T18:00:10.586000+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$hyperion_financial_management"
],
"weaknesses": []
},
"nvd": {
"cpes": [
"cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*"
],
"created": "2026-08-18T21:18:10.827000+00:00",
"description": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 4.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 4.7,
"vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
},
"cvssV4_0": {}
},
"nvd_repo_path": "2026/CVE-2026-71105.json",
"references": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"title": null,
"updated": "2026-08-24T18:38:21.913000+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$hyperion_financial_management"
],
"weaknesses": [
"CWE-269",
"CWE-284"
]
},
"opencve": {
"changes": [
{
"created": "2026-08-18T21:15:00+00:00",
"data": [
{
"details": {
"new": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 4.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"old": null
},
"type": "description"
},
{
"details": [
"oracle",
"oracle$PRODUCT$hyperion_financial_management"
],
"type": "first_time"
},
{
"details": {
"added": [
"cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
},
{
"details": {
"added": [
"oracle",
"oracle$PRODUCT$hyperion_financial_management"
],
"removed": []
},
"type": "vendors"
},
{
"details": {
"added": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {
"cvssV3_1": {
"score": 4.7,
"vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "e5762ca6-39bd-4a89-84ed-80c7a4c17ba1"
},
{
"created": "2026-08-19T08:00:00+00:00",
"data": [
{
"details": {
"new": "Denial of Service in Oracle Hyperion Financial Management via Low-Privilege Exploit",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-749"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "eb2c6aa9-7693-48e4-bea1-f1dd0ff83c63"
},
{
"created": "2026-08-19T21:00:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "Denial of Service in Oracle Hyperion Financial Management via Low-Privilege Exploit"
},
"type": "title"
},
{
"details": {
"added": [],
"removed": [
"CWE-749"
]
},
"type": "weaknesses"
}
],
"id": "999fd304-efe1-4599-8da7-4bcd7d71d257"
},
{
"created": "2026-08-20T06:30:00+00:00",
"data": [
{
"details": {
"new": "Local Denial of Service Vulnerability in Oracle Hyperion Financial Management 11.2.25.0.000",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-749"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "0b66e47b-8d86-4ae4-80fe-e1aed5b39073"
},
{
"created": "2026-08-20T18:15:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "Local Denial of Service Vulnerability in Oracle Hyperion Financial Management 11.2.25.0.000"
},
"type": "title"
},
{
"details": {
"added": [],
"removed": [
"CWE-749"
]
},
"type": "weaknesses"
}
],
"id": "a2d4fd17-4009-453d-b389-7981a30818e8"
},
{
"created": "2026-08-20T18:30:00+00:00",
"data": [
{
"details": {
"added": [
"CWE-284"
],
"removed": []
},
"type": "weaknesses"
},
{
"details": {
"added": {
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "partial"
},
"version": "2.0.3"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "91d49fb4-db96-4370-85ae-54c009ee9b8a"
},
{
"created": "2026-08-21T03:15:00+00:00",
"data": [
{
"details": {
"new": "Local Denial‑of‑Service Vulnerability in Oracle Hyperion Financial Management",
"old": null
},
"type": "title"
}
],
"id": "bc311c39-2515-4141-8f6a-f7f30f10acb6"
},
{
"created": "2026-08-24T18:45:00+00:00",
"data": [
{
"details": {
"added": [
"CWE-269"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "dc58dc2e-8406-49de-9415-a041e98d4948"
},
{
"created": "2026-08-24T21:15:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "Local Denial‑of‑Service Vulnerability in Oracle Hyperion Financial Management"
},
"type": "title"
}
],
"id": "aa4a5c66-0c88-4cf6-8ce2-9ddba46b2593"
}
],
"cpes": {
"data": [
"cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*"
],
"providers": [
"mitre",
"nvd"
]
},
"created": {
"data": "2026-08-18T21:03:32.192000+00:00",
"provider": "mitre"
},
"description": {
"data": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 4.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {
"score": 4.7,
"vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
},
"provider": "mitre"
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.00116
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "partial"
},
"version": "2.0.3"
},
"provider": "vulnrichment"
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"providers": [
"mitre",
"nvd"
]
},
"title": {
"data": null,
"provider": null
},
"updated": {
"data": "2026-08-24T21:00:13.139140+00:00",
"provider": "enrichment"
},
"vendors": {
"data": [
"oracle",
"oracle$PRODUCT$hyperion_financial_management"
],
"providers": [
"mitre",
"nvd",
"enrichment"
]
},
"weaknesses": {
"data": [
"CWE-269",
"CWE-284"
],
"providers": [
"nvd",
"vulnrichment"
]
}
},
"vulnrichment": {
"cpes": [],
"created": "2026-08-18T21:03:32.192000+00:00",
"description": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 4.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {},
"kev": {},
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "partial"
},
"version": "2.0.3"
}
},
"references": [],
"title": null,
"updated": "2026-08-20T17:47:29.475000+00:00",
"vendors": [],
"vulnrichment_repo_path": "2026/71xxx/CVE-2026-71105.json",
"weaknesses": [
"CWE-284"
]
}
}