Impact
The vulnerability resides in the server component of Oracle Hyperion Financial Reporting, allowing an attacker who has logged on to the infrastructure to create, delete, or modify data and read unauthorized portions of the system’s output. The impact is a compromise of both data integrity and confidentiality, and the CVSS vector indicates a low privilege need with no user interaction; the attack could lead to unauthorized manipulation of financial reports.
Affected Systems
Oracle Hyperion Financial Reporting version 11.2.25.0.000 is affected. No other Oracle or third-party products are listed as impacted.
Risk and Exploitability
The CVSS base score of 5.3 reflects moderate severity, with moderate likelihood of exploitation given the low required privileges and lack of network exposure. The EPSS score is very low (< 1%), indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an attacker to have local logon access to the host running Hyperion.
OpenCVE Enrichment