Impact
This vulnerability in Oracle Hyperion Financial Management version 11.2.25.0.000 allows a high‑privileged local attacker who can log on to the underlying infrastructure to compromise the application. The flaw permits unauthorized update, insert, or delete operations against data that the attacker is not authorized to handle and can also trigger a partial denial of service. The weakness is an improper access control flaw that permits escalation of privileges within the application, resulting in integrity and availability impacts as reflected by the CVSS base score of 3.0.
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000 from Oracle Corporation is affected. No additional versions or product variants are listed.
Risk and Exploitability
The CVSS score of 3.0 indicates low overall severity, and the EPSS score is not available, suggesting that widespread exploitation is currently unlikely. The vulnerability requires local high‑privileged access, limiting the attack surface. It is not listed in the CISA KEV catalog, indicating that advanced persistent threat activity targeting this bug has not been observed. The primary attack vector is local, through credentials or compromised accounts with administrative rights on the host running the application, making containment measures such as restricting who can log into the underlying infrastructure critical.
OpenCVE Enrichment