Impact
A local attacker who has obtained logon access to the infrastructure hosting Oracle Hyperion Financial Management can exploit a security flaw that bypasses authentication checks. The flaw requires the cooperation of a separate individual to complete the attack but, once executed, it allows the attacker to take full control of the application, compromising the confidentiality, integrity, and availability of financial data.
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000, a product of Oracle Corporation.
Risk and Exploitability
The vulnerability has a CVSS v3.1 score of 7.0, indicating high severity. The EPSS score is below 1 percent and the flaw is not listed in the CISA KEV catalog. The attack vector is local (AV:L); the attacker needs to be logged on to the infrastructure and rely on a separate person to provide the required human interaction. The complexity of the exploit (AC:H, PR:N) means it is difficult to carry out, yet successful exploitation results in complete takeover of the application.
OpenCVE Enrichment