PatchSiren

Oracle CVE debriefs · Page 7

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Oracle CVE published 2026-08-18

CVE-2026-71119

The CVE-2026-71119 vulnerability affects Oracle Hyperion Financial Management version 11.2.25.0.000, a difficult-to-exploit vulnerability that allows high-privileged attackers with logon to the infrastructure to compromise the system. Successful attacks can result in takeover of Oracle Hyperion Financial Management. The CVSS 3.1 Base Score is 6.4, indicating a medium severity level. Oracle Hyperion Financ [truncated]

MEDIUM Oracle CVE published 2026-08-18

CVE-2026-71118

The CVE-2026-71118 vulnerability in Oracle Hyperion Financial Management 11.2.25.0.000 is a difficult-to-exploit vulnerability that allows unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized update, insert, or delete access to some accessible data and unauthorized read access to a subset of accessible data. The CVSS score is 4.8, i [truncated]

HIGH Oracle CVE published 2026-08-18

CVE-2026-71117

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:18:12.350Z and has not been modified since then. The vulnerability affects Oracle Hyperion Financial Management version 11.2.25.0.000, allowing high privileged attackers with logon to the infrastructure to compromise the product. Successful attacks can result in takeover of Oracle Hyperion Fin [truncated]

HIGH Oracle CVE published 2026-08-18

CVE-2026-71110

The CVE-2026-71110 vulnerability affects the Helidon product of Oracle Fusion Middleware, specifically the Imperative Web Server component. The supported version that is affected is 4.5.0. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTPS to compromise Helidon, resulting in unauthorized creation, deletion, or modification access to critical data or all He [truncated]

MEDIUM Oracle CVE published 2026-08-18

CVE-2026-71108

The CVE-2026-71108 vulnerability is a medium-severity issue in Oracle Hyperion Financial Management, version 11.2.25.0.000. It is a difficult-to-exploit vulnerability that allows low-privileged attackers with network access via HTTP to compromise the system and gain unauthorized access to critical data. The CVSS 3.1 Base Score is 5.3, indicating a medium severity. The vector is CVSS:3.1/AV:N/AC:H/PR:L/UI: [truncated]

MEDIUM Oracle CVE published 2026-08-18

CVE-2026-71090

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:18:09.200Z and has not been modified since then. The CVE-2026-71090 vulnerability is a medium-severity issue in Oracle Hyperion Financial Management version 11.2.25.0.000. It allows a low-privileged attacker with network access via HTTP to potentially cause a hang or frequently repeatable cras [truncated]

CRITICAL Oracle CVE published 2026-08-18

CVE-2026-71064

The Portable Clusterware component of Oracle Database Server contains a vulnerability that allows an unauthenticated attacker with access to the physical communication segment to compromise the server. This vulnerability affects Oracle Database Server versions 19.3-19.32, 21.3-21.23, and 23.4.0-23.26.3. The vulnerability has a CVSS 3.1 Base Score of 9.6, indicating a critical severity level. Successful at [truncated]

HIGH Oracle CVE published 2026-08-18

CVE-2026-71048

A vulnerability in Oracle Product Lifecycle Analytics allows low-privileged attackers with network access via HTTP to compromise the product, potentially leading to unauthorized data access, modification, and partial denial of service. The vulnerability, tracked as CVE-2026-71048, affects version 3.6.1 of the product and has a high CVSS score of 7.6. Defenders should prioritize verifying exposure, applyin [truncated]

CRITICAL Oracle CVE published 2026-08-18

CVE-2026-71037

A critical vulnerability exists in Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. This easily exploitable vulnerability allows unauthenticated attackers with network access via HTTP to compromise the product. Successful attacks require human interaction and can significantly impact additional products, leading to unauthorized creation, deletion, or modification of criti [truncated]

MEDIUM Oracle CVE published 2026-08-18

CVE-2026-71029

The CVE-2026-71029 vulnerability affects the Helidon product of Oracle Fusion Middleware, specifically the Imperative Web Server component. Versions 3.0.0-3.2.17 are supported and affected. The vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Helidon, potentially impacting additional products. Successful attacks can result in unauthorized access to critical data [truncated]

HIGH Oracle CVE published 2026-08-18

CVE-2026-70924

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:50.280Z and has not been modified since then. Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticate [truncated]

CRITICAL Oracle CVE published 2026-08-18

CVE-2026-70905

The CVE-2026-70905 vulnerability affects Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0, allowing unauthenticated attackers with network access via SAML to compromise the system. This critical vulnerability has a CVSS score of 9.8, indicating high severity. Successful attacks can result in a complete takeover of Oracle Access Manager. Organizations should prioritize patching to prevent potential [truncated]

HIGH Oracle CVE published 2026-08-18

CVE-2026-70887

CVE-2026-70887 is a vulnerability in Oracle Hyperion Data Relationship Management, specifically in the Access and security component. The affected version is 11.2.25.0.000. This easily exploitable vulnerability allows unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Hyperi [truncated]

HIGH Oracle CVE published 2026-08-18

CVE-2026-70879

The CVE-2026-70879 vulnerability is a difficult-to-exploit issue in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion, specifically in the Access and security component. The supported version that is affected is 11.2.25.0.000. This vulnerability allows a low-privileged attacker with logon access to the infrastructure where Oracle Hyperion Data Relationship Management executes to [truncated]

HIGH Oracle CVE published 2026-08-18

CVE-2026-70870

The CVE-2026-70870 vulnerability affects Oracle Hyperion Data Relationship Management version 11.2.23.0.000, specifically in the Web Client - Unicode component. This vulnerability allows unauthenticated attackers with network access via HTTP to compromise the system, potentially leading to unauthorized access to critical data or partial denial of service. The CVSS 3.1 Base Score is 8.2, indicating high se [truncated]

LOW Oracle CVE published 2026-08-18

CVE-2026-70853

The CVE-2026-70853 vulnerability is a difficult-to-exploit issue in Oracle Hyperion Financial Management version 11.2.25.0.000. It allows high privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data and partial denial of service. Oracle Hyperion Financial Management users [truncated]

LOW Oracle CVE published 2026-08-18

CVE-2026-70851

The CVE-2026-70851 vulnerability affects Oracle Hyperion Financial Management, version 11.2.25.0.000. It is a difficult-to-exploit vulnerability that allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to partial denial of service. The CVSS score is 3.1, indicating low severity. This vulnerability is challenging to exploit and requires specific condit [truncated]

LOW Oracle CVE published 2026-08-18

CVE-2026-70850

The CVE-2026-70850 vulnerability affects Oracle Hyperion Financial Management version 11.2.25.0.000, classified as a difficult-to-exploit vulnerability allowing high privileged attackers with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise the system. Successful attacks can result in unauthorized update, insert or delete access to some accessible data and unau [truncated]

MEDIUM Oracle CVE published 2026-08-18

CVE-2026-70780

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:31.220Z and has not been modified since then. The CVE-2026-70780 vulnerability affects Oracle Hyperion Financial Reporting version 11.2.25.0.000, a difficult-to-exploit vulnerability allowing unauthenticated attackers with access to the physical communication segment to compromise the syste [truncated]

MEDIUM Oracle CVE published 2026-08-18

CVE-2026-70775

The CVE-2026-70775 vulnerability is in the Oracle Installed Base product of Oracle E-Business Suite (component: User Interface), affecting versions 12.2.3-12.2.15. It is an easily exploitable vulnerability that allows a low-privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks can result in unauthorized update, insert or delete access to some of Oracle In [truncated]

MEDIUM Oracle CVE published 2026-08-18

CVE-2026-70769

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:29.660Z and has not been modified since then. The CVE-2026-70769 vulnerability is a difficult-to-exploit vulnerability in Oracle Hyperion Financial Reporting, allowing unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthori [truncated]

MEDIUM Oracle CVE published 2026-08-18

CVE-2026-70768

The CVE-2026-70768 vulnerability affects Oracle Hyperion Financial Reporting version 11.2.25.0.000, specifically in the Server component. This vulnerability is classified as easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation requires human interaction from a person other than the attacker and can impact additional products beyond Oracle Hyperion Financi [truncated]

HIGH Oracle CVE published 2026-08-18

CVE-2026-70764

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:29.060Z and has not been modified since then. CVE-2026-70764 is a vulnerability in Oracle General Ledger, allowing low-privileged attackers with network access via HTTP to compromise data confidentiality, integrity, and availability. The vulnerability has a CVSS 3.1 Base Score of 7.6, indic [truncated]

MEDIUM Oracle CVE published 2026-08-18

CVE-2026-70758

The CVE-2026-70758 vulnerability affects the Oracle Hyperion Financial Reporting product, specifically version 11.2.25.0.000. This difficult-to-exploit vulnerability allows low-privileged attackers with logon access to compromise the system, potentially leading to unauthorized creation, deletion, or modification of critical data and unauthorized read access to a subset of accessible data. The CVSS 3.1 Bas [truncated]

MEDIUM Oracle CVE published 2026-08-18

CVE-2026-70754

The CVE-2026-70754 vulnerability in Oracle Hyperion Financial Reporting (component: Server) is a critical issue that allows unauthenticated attackers with network access via HTTP to compromise the system, potentially leading to unauthorized read access to a subset of accessible data. Organizations using Oracle Hyperion Financial Reporting version 11.2.25.0.000 should prioritize patching this vulnerability [truncated]

MEDIUM Oracle CVE published 2026-08-18

CVE-2026-70753

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:28.113Z and has not been modified since then. The CVE-2026-70753 vulnerability affects Oracle Hyperion Financial Reporting version 11.2.25.0.000, allowing low-privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized data access or modif [truncated]

HIGH Oracle CVE published 2026-08-18

CVE-2026-70752

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:28.007Z and has not been modified since then. CVE-2026-70752 is a high-severity vulnerability in Oracle Hyperion Financial Reporting, specifically in the Server component, affecting version 11.2.25.0.000. This vulnerability allows unauthenticated attackers with network access via HTTP to co [truncated]

MEDIUM Oracle CVE published 2026-08-18

CVE-2026-70751

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:27.897Z and has not been modified since then. The CVE-2026-70751 vulnerability affects Oracle Hyperion Financial Reporting version 11.2.25.0.000, a difficult-to-exploit vulnerability allowing unauthenticated attackers with network access via HTTP to compromise the system, requiring human in [truncated]

HIGH Oracle CVE published 2026-08-18

CVE-2026-70749

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:27.680Z and has not been modified since then. The CVE-2026-70749 vulnerability is a difficult-to-exploit vulnerability in Oracle Hyperion Financial Reporting version 11.2.25.0.000. It allows unauthenticated attackers with network access via HTTP to compromise Oracle Hyperion Financial Repor [truncated]

HIGH Oracle CVE published 2026-08-18

CVE-2026-70746

The CVE-2026-70746 vulnerability affects Oracle Hyperion Financial Reporting version 11.2.25.0.000, allowing unauthenticated attackers with network access via HTTP to compromise the system. This vulnerability has a high CVSS severity score of 8.1, impacting confidentiality and integrity. Organizations should verify their deployments and apply patches. The vulnerability requires human interaction and can r [truncated]