Impact
A vulnerability in the security component of Oracle Hyperion Financial Management allows an attacker with low‑privilege access to the infrastructure where the application runs to compromise the system. The underlying weakness is an improper access control vulnerability (CWE-269 / CWE-284). The flaw permits creation, deletion or modification of critical data, and grants full access to all data available through the application. This results in a significant compromise of both confidentiality and integrity of the organization’s financial information.
Affected Systems
The affected product is Oracle Hyperion Financial Management version 11.2.25.0.000, released by Oracle Corporation.
Risk and Exploitability
The CVSS 3.1 base score is 7.1 with an attack vector of local, attack complexity of low, and required privileges of low, indicating that the vulnerability can be exploited by a user who already has legitimate logon to the host. Based on the CVSS vector provided in the input, this attack vector inference is derived from the input data. The exploit would not require network exposure or user interaction, making it relatively easy to carry out locally. The EPSS score is less than 1% and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, but the high confidentiality and integrity impact means the risk is still considerable for organizations that host the application.
OpenCVE Enrichment