Impact
The flaw resides in the security component of Oracle Hyperion Financial Management, permitting a high‑privileged attacker with network SQL access to circumvent authentication and alter the system’s financial records. Such misuse can cause unauthorized creation, deletion, or modification of sensitive data, thereby undermining both confidentiality and integrity. The impact is that attackers can manipulate or expose all data the application protects.
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000 is affected. No other versions are mentioned as vulnerable. Attackers must target this specific release running the vulnerable component.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates moderate severity with high confidentiality and integrity impact. The EPSS score being below 1% signals a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the exploit requires a high‑privileged attacker who already has database connectivity; once that privilege is attained, the vulnerability is easily exploitable without additional user interaction. The threat vector is inferred to be network‑based SQL access, as the description indicates a need for network access via SQL.
OpenCVE Enrichment