Impact
A vulnerability in the Security component of Oracle Hyperion Financial Management allows an attacker with low privileges and network access via SQL to execute statements that create, delete or modify critical data. The flaw can also be used to read protected data, effectively giving the attacker unauthorized access to all information the application permits. The primary impact is loss of data integrity and confidentiality. No arbitrary code execution is disclosed.
Affected Systems
Oracle Hyperion Financial Management, version 11.2.25.0.000, provided by Oracle Corporation.
Risk and Exploitability
The CVSS 3.1 base score is 8.1, reflecting high confidentiality and integrity impacts with a low complexity attacker effort. The EPSS score is below 1%, indicating a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack path involves SQL injection over the network into the application’s database interface, requiring only a user account with limited privileges. The scope is limited to the affected product version; later releases are presumed patched.
OpenCVE Enrichment