Impact
The vulnerability arises from the Security component of Oracle Hyperion Financial Management, allowing an attacker with low privileges and network access to send arbitrary SQL commands. This flaw enables the attacker to obtain full control over the application, including the ability to read or modify any data and to take over the system. As a result, confidentiality, integrity, and availability are all severely impacted, matching the CVSS vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
Affected Systems
Affected are users running Oracle Hyperion Financial Management version 11.2.25.0.000. No other versions are known to be impacted, but users should verify their deployment against the security alert for changes.
Risk and Exploitability
With a CVSS 3.1 base score of 8.8 the vulnerability is considered high severity. The EPSS score is < 1%, indicating a very low but nonzero probability of exploitation, and the vulnerability is not yet listed in CISA KEV. The likely attack vector is network-based, requiring the attacker to send crafted SQL statements to the vulnerable component. The low attack complexity and low privileges required for exploitation mean that any host with network connectivity to the Hyperion instance could be used as a launch point, making the risk significant for exposed systems.
OpenCVE Enrichment