Impact
This local security flaw in Oracle Hyperion Financial Management version 11.2.25.0.000, documented as CWE-200, allows an attacker who can log onto the infrastructure where the application runs to read a subset of data that is normally protected. The defect resides in the Security component and represents a confidentiality breach. The CVSS 3.1 vector indicates a local attack (AV:L) with low complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N), and unchanged scope (S:U); it produces a 4.0 Base Score that impacts confidentiality only.
Affected Systems
The affected product is Oracle Hyperion Financial Management, version 11.2.25.0.000, which is part of the Oracle Hyperion suite of financial management tools. No other versions or components are listed as vulnerable.
Risk and Exploitability
Because the attacker must already have local access to the application host, the vulnerability cannot be exploited remotely. The attack requires low effort, no privileges, and no user interaction, making it relatively easy for a local adversary to read protected data. With a CVSS score of 4.0 the severity is moderate, but the EPSS score of approximately 0.13% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating that no widespread exploitation has been documented at this time.
OpenCVE Enrichment