Impact
The flaw is in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. It can be exploited by an attacker who has low‑privilege credentials and can log on the infrastructure where the application runs. The vulnerability allows the attacker to compromise the application, potentially exposing confidential data. The CVSS vector (AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N) indicates that the exploit requires local access, low effort, and no user interaction, and that successful exploitation can change the scope to affect additional products.
Affected Systems
Oracle Corporation’s Hyperion Financial Management product, specifically version 11.2.25.0.000, is affected. No other versions are listed as vulnerable.
Risk and Exploitability
The CVSS base score of 6.5 marks this flaw as a medium‑severity vulnerability. Because the EPSS score is < 1%, the exploitation probability is very low but not zero. The vulnerability is not listed in the CISA KEV catalog, but the local attack surface and the possibility of scope expansion mean that a breach could lead to unauthorized access to critical data. Attackers need only local login with low privileges, and no user interaction is required, making the threat realistic in environments where internal users have such access.
OpenCVE Enrichment