Impact
A low‑privileged attacker with local access to the infrastructure where Oracle Hyperion Financial Management executes can create, delete or modify critical data. The attacker must have some level of logon and a human interaction from another person, which is required for the attack to succeed. The resulting compromise affects the integrity of financial information, potentially leading to inaccurate reporting and financial loss.
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000 is affected. Although the vulnerability is specific to that product, it may also impact other Oracle components that interact with the affected system.
Risk and Exploitability
The CVSS 3.1 base score of 5.3 indicates a moderate severity. Because the exploitation requires local access, high attack complexity, low privileges and user interaction, the risk of successful exploitation is relatively low. The EPSS score of < 1%, or roughly 0.12%, reflects an even lower exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, reducing the likelihood of widespread exploitation. Nonetheless, if an attacker gains local access, the ability to alter critical financial data can have significant business impact, and the scope change implies that related products may also be at risk.
OpenCVE Enrichment