Impact
Vulnerability in Oracle Hyperion Financial Management allows a low‑privileged attacker with network access via HTTP to alter or read data, but it requires the involvement of a user other than the attacker. The effect is limited to unauthorized update, insert or delete of some accessible data and unauthorized read of a subset of data, resulting in modest confidentiality and integrity impact as reflected by a CVSS 3.1 base score of 4.4.
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000.
Risk and Exploitability
The vulnerability is not listed in the CISA KEV catalog and the EPSS score of less than 1% indicates a very low probability of exploitation. The CVSS score of 4.4 indicates modest risk, with high attack complexity, low privilege required, and user interaction needed. The vulnerability resides in the security component and may affect other related products due to a change in scope, but an attacker would still need valid network access to the Hyperion instance and must engage a separate user to succeed.
OpenCVE Enrichment