Impact
This vulnerability allows a low‑privileged user who can log on to the infrastructure hosting Oracle Hyperion Financial Management to compromise the application. By exploiting the flaw, an attacker can gain unauthorized access to critical financial data, or in the worst case, obtain complete access to all data the application serves. The weakness directly impacts confidentiality and is classified as a local access vulnerability.
Affected Systems
The affected product is Oracle Hyperion Financial Management, version 11.2.25.0.000.
Risk and Exploitability
The CVSS 3.1 base score of 5.5 indicates moderate severity with high confidentiality impact. The exploit requires local access and low privilege, and the attacker does not need a UI or additional authentication beyond local logon. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation, yet the low‑privilege requirement means internal actors pose significant risk.
OpenCVE Enrichment