Impact
The vulnerability is a broken access control flaw in the Security component of Oracle Hyperion Financial Management 11.2.25.0.000. A local attacker who possesses high‑privileged access to the infrastructure hosting the application can modify, delete, or read data that should be protected. This weakness is classified as CWE‑284 and results in confidential and integrity impacts of low severity, as reflected in a CVSS base score of 3.0.
Affected Systems
Oracle Corporation’s Oracle Hyperion Financial Management version 11.2.25.0.000 is the only affected product version identified by the CVE.
Risk and Exploitability
The CVSS score of 3.0 indicates a low overall threat, and exploitation requires local access with high privileges, making it more difficult to achieve. The EPSS score of < 1% and lack of listing in CISA’s KEV catalog suggest that widespread exploitation has not been observed. Nonetheless, an attacker who gains a privileged local account can still alter financial data or gain unauthorized viewing rights. Organizations should therefore treat this risk as low but present and consider mitigation measures.
OpenCVE Enrichment