Impact
Oracle Hyperion Financial Reporting version 11.2.25.0.000 contains an unauthorized access flaw that enables an attacker with physical network access to the server’s communication segment to create, delete, or modify critical data. The flaw is a weakness in access control that can be exploited without authentication, and availability is unaffected. The CVSS v3.1 score of 6.8 reflects significant confidentiality and integrity loss while availability is unaffected.
Affected Systems
The vulnerability affects Oracle Hyperion Financial Reporting, a product of Oracle Corporation, in its 11.2.25.0.000 release. No other versions or components are known to be impacted.
Risk and Exploitability
The vector is local physical access (AV:A) and the attack is difficult to execute, yet possible if an adversary controls the network segment of the hardware running Oracle Hyperion. With a CVSS base score of 6.8 and an EPSS score of < 1%, the likelihood of exploitation is very low; it is not listed in the CISA KEV catalog. The breach would allow an attacker to alter or delete financial data, undermining the integrity of the reporting system.
OpenCVE Enrichment