Impact
The vulnerability resides in the Oracle Hyperion Financial Management component responsible for security. An attacker who is low privileged and can send SQL statements over the network can exploit this flaw. Successful exploitation could lead to full takeover of the application, exposing all data and enabling the attacker to modify or delete records. The weakness results in complete loss of confidentiality, integrity and availability, reflecting the high CVSS score and the described impact on all three core assets.
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000 is impacted. The issue is identified in the Hyperion Security component.
Risk and Exploitability
This flaw scores 8.8 on CVSS 3.1, indicating a high‑severity risk. The vectors indicate a network‑based attack with low attack complexity and low privileges, and no user interaction is required. The EPSS score of < 1 % indicates a low but nonzero exploitation probability. Although the vulnerability is not listed in CISA’s KEV catalog, its high CVSS score, easy exploitability, and the presence of an EPSS rating make it a high‑threat vulnerability for any system still running the affected version.
OpenCVE Enrichment