Impact
The vulnerability resides in the Security component of Oracle Hyperion Financial Management and permits an attacker with low privileges and network access to the database via SQL to compromise the product. This easily exploitable flaw can result in full takeover of the application, producing severe confidentiality, integrity, and availability impacts, as indicated by the CVSS 3.1 base score of 8.8.
Affected Systems
Oracle Hyperion Financial Management, version 11.2.25.0.000 is the only publicly documented affected release. The vulnerability applies to the Security component within this Oracle product, impacting all installations of that version lacking the vendor's patch.
Risk and Exploitability
The risk is high due to a CVSS score of 8.8, with the attacker only needing low privileges and network connectivity via SQL. No EPSS data is available, and the vulnerability is not listed in CISA KEV, but its simplicity and the critical nature of the target warrant prompt remediation. Attackers could exploit this vector remotely, so patching should be prioritized.
OpenCVE Enrichment