Impact
The vulnerability resides in the Server component of Oracle Hyperion Financial Reporting version 11.2.25.0.000 and allows a low‑privileged attacker who can log on to the underlying host to create, delete, or modify critical application data, resulting in a loss of data integrity. The weakness is rooted in insufficient access controls (CWE-284), as reflected by a CVSS 3.1 base score of 4.7 that impacts integrity.
Affected Systems
Oracle Hyperion Financial Reporting, version 11.2.25.0.000, is affected. The flaw is limited to the Server component and impacts any installation matching the specified version.
Risk and Exploitability
The description indicates that the attacker must already have a logon to the host, implying a local attack vector. The CVSS score signals a moderate integrity risk, and the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, further reducing urgency. Successful exploitation requires local privileges and access to the Hyperion server infrastructure, and hinges on the product's failure to enforce proper access controls.
OpenCVE Enrichment