Impact
The vulnerability is situated in the Security component of Oracle Hyperion Financial Management. An attacker who has local high privileges on the host where the application runs can exploit this flaw, enabling them to compromise the Hyperion environment and trigger a partial denial of service. The effect is limited to availability; no unauthorized data disclosure or modification is possible.
Affected Systems
Affected systems are Oracle Corporation’s Hyperion Financial Management product, specifically version 11.2.25.0.000. No other versions are listed in the advisory.
Risk and Exploitability
The CVSS v3.1 base score of 1.9 indicates low severity with an availability impact. The EPSS score is under 1 %, reflecting a very low probability of exploitation, and the vulnerability is not catalogued in CISA KEV. Exploitation requires local access and high privileged shell, restricting the attack surface. Overall risk remains modest, but organizations should remain alert for unexpected availability disruptions.
OpenCVE Enrichment