Impact
A flaw in Oracle Hyperion Financial Reporting allows an attacker who has logged on to the underlying infrastructure to create, delete, modify or read data that should be protected. The weakness results in loss of data integrity and confidentiality for all accessible data. The CVSS vector indicates a local attack with high authentication requirements and low impact on availability.
Affected Systems
Oracle Corporation’s Hyperion Financial Reporting, version 11.2.25.0.000, is affected.
Risk and Exploitability
The CVSS score of 5.3 classifies the vulnerability as moderate severity. Exploitation requires the attacker to have a legitimate logon to the system, suggesting a local or possession‑based attack surface. EPSS score of <1% indicates a very low exploitation probability and the vulnerability is not listed in the CISA KEV catalog, indicating limited public exploitation evidence.
OpenCVE Enrichment