Impact
The vulnerability is located in the Security component of Oracle Hyperion Financial Management. This flaw involves improper authorization and privilege management, corresponding to CWE-284. A local, high‑privilege attacker who has logged on to the infrastructure hosting the application can exploit this weakness to completely compromise the application, leading to full confidentiality, integrity, and availability loss.
Affected Systems
Oracle Corporation's Oracle Hyperion Financial Management, version 11.2.25.0.000. The vulnerability is present only in this exact build of the product and does not affect other versions or unrelated Oracle software.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates a high impact, and the vector (AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H) shows that the exploit requires local access and high privileges but does not require user interaction. Successful exploitation results in a scope change, allowing the attacker to takeover the application and potentially affect other connected products. The EPSS score is < 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, so the immediate threat level remains governed primarily by the high CVSS score and the local privilege requirement.
OpenCVE Enrichment