Impact
Oracle Hyperion Financial Management is vulnerable to an easily exploitable flaw that allows a low‑privileged attacker with network access to the database to execute arbitrary SQL commands. The vulnerability affects the Security component of version 11.2.25.0.000 and can lead to full takeover of the Hyperion instance, compromising confidentiality, integrity and availability of the financial data. The CVSS score of 8.8 indicates a high‑severity risk and reflects the potential for complete control over the system if exploited.
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000 is the only affected product, as identified by the CNA. No other versions or products are listed as impacted.
Risk and Exploitability
The CVSS vector reveals that the attack can be launched over the network (AV:N) with low attack complexity (AC:L) and requires low privileges (PR:L). Because the vector also shows no user interaction (UI:N) and impacts only a single system (S:U), the vulnerability can be exploited remotely by an adversary with basic database access. EPSS data is not available, and the vulnerability is not in CISA’s KEV catalog, but the high CVSS still signals a readily exploitable threat that can lead to takeover of the financial management system.
OpenCVE Enrichment