Impact
Based on the description, it is inferred that the vulnerability represents an Improper Access Control flaw (CWE-284) and a Privilege Management flaw (CWE-269) in the security component of Oracle Hyperion Financial Management. It allows a local user with low privileges to compromise the application and read or modify critical financial data. This flaw results in confidentiality loss as sensitive information becomes accessible to unauthorized parties.
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000 is the only product impacted by this vulnerability.
Risk and Exploitability
The CVSS base score of 5.6 indicates a medium severity. Exploitation requires an existing low‑privileged local account and occurs over a local attack vector (AV:L). The EPSS score is less than 1%, indicating a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Yet the local nature means an attacker who can log on to the infrastructure hosting the application could successfully gain unauthorized access and, due to a scope change, potentially affect other related products.
OpenCVE Enrichment