Impact
The flaw lies in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000 and permits a low-privileged local user who can log onto the host to read, insert, update or delete protected financial records. The resulting breach allows attackers to compromise confidential information and alter data integrity, matching the CVSS profile of high confidentiality impact and low integrity impact.
Affected Systems
Oracle Hyperion Financial Management released by Oracle Corporation in version 11.2.25.0.000 is affected. No other versions or components are reported as vulnerable.
Risk and Exploitability
The vulnerability is exploitable locally: an attacker must first obtain a legitimate host login, then may leverage the flaw without further privileges. The CVSS score of 6.1 indicates moderate severity, and the EPSS score (< 1 % ) suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, but given the sensitivity of financial data it warrants prompt attention and remediation.
OpenCVE Enrichment