Impact
A flaw in Oracle Hyperion Financial Management 11.2.25.0.000 allows an attacker who can physically access the hardware's communication segment to bypass all authentication and authorization checks, representing a CWE-200 (Missing Authentication Protection) and CWE-269 (Improper Privilege Management) weakness. Exploiting this vulnerability grants the attacker the ability to create, delete or modify critical financial records, thereby breaching confidentiality and integrity of all data stored by the application.
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000, distributed by Oracle Corporation.
Risk and Exploitability
The flaw carries a CVSS v3.1 base score of 8.1, indicating high severity, and it is accessed locally via a physical attack vector (AV:A). Although the EPSS score is below 1% and the vulnerability is not listed in CISA's KEV catalog, the required physical access means that an insider or an individual with physical proximity can readily exploit the flaw. Successful exploitation can result in unilateral unauthorized manipulation of all financial data, presenting a serious risk to organizations that lack strict physical security controls around Hyperion servers.
OpenCVE Enrichment