Impact
In Oracle Hyperion Financial Management version 11.2.25.0.000, a local access control weakness (CWE-284) combined with improper privilege management lets a low‑privileged attacker who can log on locally compromise the application. The flaw, requiring interaction with a non‑attacker, permits unauthorized updating, inserting, or deleting of restricted data, unauthorized reading of data, and a partial denial of service.
Affected Systems
Oracle Corporation's Oracle Hyperion Financial Management version 11.2.25.0.000 running on the infrastructure it is deployed on.
Risk and Exploitability
The CVSS 3.1 base score is 4.2, indicating low‑severity risk. The EPSS score is < 1%, and it is not listed in the CISA KEV catalog. Because the attack vector is local (AV:L) and an additional person's cooperation (UI:R) is required, the likelihood of exploitation is low in typical environments. Exploitation would allow an attacker limited access to modify or read data and launch intermittent service interruptions, but it would not provide full control of the system or application. The impact is therefore restricted to unauthorized data disclosure, modification and partial availability loss.
OpenCVE Enrichment