Impact
A local attacker who possesses high‑privileged credentials on the host where Oracle Hyperion Financial Management runs can exploit a flaw in the product’s security component. The vulnerability is difficult to exploit, but when successful it provides full control over the application, allowing the attacker to read, modify, or delete data and potentially disrupt service availability. The impact covers confidentiality, integrity and availability of the Hyperion application data. The weakness is consistent with a privilege‑escalation flaw classified as CWE-284.
Affected Systems
The flaw affects Oracle Corporation’s Hyperion Financial Management, version 11.2.25.0.000, in the security component of the product.
Risk and Exploitability
The base CVSS score of 6.4 indicates a moderate severity, with the attack vector limited to local access (AV:L) and requiring high privileged user rights (PR:H). Because the attacker must already have a logon on the infrastructure that hosts Hyperion, the exploit is not remotely achievable from outside the network. EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, which suggests that widespread exploitation has not yet been observed. However, the potential for full application takeover warrants proactive mitigation.
OpenCVE Enrichment