Impact
The vulnerability lies in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. An attacker with local logon to the host can retrieve a subset of confidential data without authenticating to Hyperion. Successful exploitation permits reading protected data, resulting in a confidentiality breach while leaving integrity and availability unaffected.
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000 is affected. The product is part of Oracle Hyperion, a financial management solution used for reporting and planning.
Risk and Exploitability
The CVSS 3.1 base score of 4.0 indicates a low impact on confidentiality. The attack vector is local (AV:L) and requires low effort (AC:L), so an attacker must have access to the host where Hyperion runs. The EPSS score is less than 1%, suggesting a very low probability of exploitation, and the vulnerability is not listed in CISA's KEV catalog. Because this flaw allows unauthenticated local read access to restricted data, organizations should enforce strict local access controls and consider immediate patching if a fix is available.
OpenCVE Enrichment