Impact
The flaw exists in the Security component of Oracle Hyperion Financial Management and permits a high‑privileged user who has logon access to the underlying infrastructure to compromise the application. Successful exploitation allows the attacker to create, delete, or modify critical data and obtain broad, unrestricted access to all data available through the application, thereby violating confidentiality and integrity.
Affected Systems
Affected vendor is Oracle Corporation, product Oracle Hyperion Financial Management, version 11.2.25.0.000.
Risk and Exploitability
The CVSS 3.1 base score of 6.0 reflects moderate severity, and the EPSS score of < 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA KEV. The attack vector is local with low complexity, high privileges, no user interaction, and the scope remains unchanged. An attacker with such privileges can directly manipulate application data without further escalation.
OpenCVE Enrichment