Impact
The vulnerability is an easily exploitable SQL injection flaw in the security component of Oracle Hyperion Financial Management. A low-privileged attacker who can send SQL commands over the network can walk into the application and ultimately gain full control of the system, compromising confidentiality, integrity, and availability of the platform.
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000 is affected. Because the flaw causes a change of scope, the compromise could extend to other products that interact with Hyperion.
Risk and Exploitability
With a CVSS 3.1 base score of 9.9, this vulnerability is critical. The EPSS score is < 1%, indicating a very low but non-zero exploitation probability. The issue is not listed in the CISA KEV catalog. The advisory indicates a low-privileged attacker with network access can exploit the SQL injection in the security component to gain full control of the system, compromising confidentiality, integrity, and availability.
OpenCVE Enrichment