Impact
The vulnerability resides in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. A low‑privileged local account on the host where the application runs can exploit this flaw to create, delete, or modify critical financial data, or to obtain full read access to all Hyperion‑managed data, thereby compromising confidentiality and integrity.
Affected Systems
Affected systems include Oracle Hyperion Financial Management 11.2.25.0.000 deployed by Oracle Corporation. Because the flaw touches a core security mechanism, other Oracle products that share the same infrastructure or database can also be impacted if the exploitation scope expands.
Risk and Exploitability
The CVSS 3.1 Base Score of 8.4 indicates high severity with local availability, low access complexity, low privileges, and no user interaction. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog. The description infers that an attacker must already have logged on to the host running Hyperion; once local foothold is achieved, the impact extends to the entire Hyperion instance and potentially to other Oracle products on the same system.
OpenCVE Enrichment