Impact
A flaw in the security component of Oracle Hyperion Financial Management allows an attacker logged on with low privileges to the host machine to gain unauthorized control over the application, enabling creation, deletion, or modification of critical financial data and full read access to confidential information. The vulnerability is local, requires minimal effort, and can be leveraged to alter or destroy key data within the system.
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000 is affected; the issue is confined to the Security component of this specific release.
Risk and Exploitability
The CVSS 3.1 base score of 8.4 indicates high severity, with local access, low attacker effort, low privilege, and a scope change that could impact other products. The EPSS score is <1%, indicating a very low but non‑zero exploitation probability. Although not listed in the CISA KEV catalog, the potential for widespread data tampering makes this a critical vulnerability that should be addressed promptly.
OpenCVE Enrichment