Impact
The vulnerability resides in the security component of Oracle Hyperion Financial Management and can be triggered by an unauthenticated attacker who can reach the system over HTTPS. An attacker who successfully exploits this weakness can create, delete or modify critical data, or gain complete access to all data available to the Hyperion system, thereby compromising confidentiality and integrity. The CVSS base score of 8.7 reflects these significant impacts on data integrity and confidentiality. This does not affect availability. The weakness is a consequence of improper access control or privilege management that allows scope change, meaning an attacker may elevate privileges to affect more data than initially permitted.
Affected Systems
The affected product is Oracle Hyperion Financial Management, version 11.2.26.0.000, as listed under the Oracle product name in the advisory. No other products or versions are explicitly enumerated as affected.
Risk and Exploitability
The CVSS vector indicates an attacker can pursue the flaw over the network with no user interaction and only a high complexity of exploit, but no privileged access is required. The EPSS score is less than 1%, suggesting a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However, the scope change still raises the risk because the flaw can be used to alter data beyond the initial compromise window. Consequently, organizations running this version should consider the flaw a high-severity risk until a patch is applied.
OpenCVE Enrichment