Impact
The vulnerability resides in the Security component of Oracle Hyperion Financial Management and permits an unauthenticated attacker who has logged onto the same infrastructure to compromise the application. If the attacker can persuade a separate user to interact with the system, they can gain unauthorized update, insert or delete permissions to data accessible through the application, thereby compromising data integrity.
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000, distributed by Oracle Corporation, is the only product listed as affected.
Risk and Exploitability
The CVSS 3.1 score is 2.5, indicating a low to moderate risk. EPSS score of 0.00124 (<1%) indicates a very low exploitation probability and the vulnerability is not listed in CISA KEV. The attack requires local logon credentials and a human interaction from another user, limiting the exploitation surface, but still permitting integrity violations if the conditions are met.
OpenCVE Enrichment