Impact
A flaw in the Security component of Oracle Hyperion Financial Management allows a local attacker with low privileges who can log on to the host where the application runs to cause the application to hang or repeatedly crash, resulting in a loss of availability. This weakness is a form of unauthorized access (CWE‑284) that affects only availability, leaving confidentiality and integrity untouched.
Affected Systems
Oracle Hyperion Financial Management 11.2.25.0.000 is the only technical version that is identified as vulnerable in the CVE data. The product is distributed by Oracle Corporation.
Risk and Exploitability
The CVSS 3.1 base score of 4.7 reflects a high impact on availability with local access (AV:L) and low privilege (PR:L). The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating that widespread exploitation is unlikely. Nonetheless, because an adversary who can log on locally can trigger repeated crashes, the overall risk can be considered moderate given the limited exploitation conditions.
OpenCVE Enrichment