Impact
The vulnerability allows an attacker with low‑privilege access to a host where Oracle Hyperion Financial Reporting runs to compromise the application, resulting in a full takeover that compromises confidentiality, integrity, and availability. The flaw is rated CVSS 7.8 with impact on all asset properties, indicating significant damage if exploited.
Affected Systems
Affected: Oracle Hyperion Financial Reporting Server component, version 11.2.25.0.000. No other Oracle or third‑party versions are explicitly listed as vulnerable.
Risk and Exploitability
The risk is high due to the local nature of the required access, the availability of patch information, and the lack of an existing exploit reference. The vulnerability can be easily leveraged by any local user who can log on to the infrastructure, making it a straightforward local privilege escalation vector that leads to total application compromise. It is not listed in the CISA KEV catalog and EPSS data is unavailable; however, advisories indicate that the flaw is considered a high‑impact issue.
OpenCVE Enrichment