Impact
A low‑privileged attacker with network access through HTTP can exploit a weakness in the Security component of Oracle Hyperion Financial Management. Once activated, the flaw permits unauthorized reading and modification of critical data, potentially granting read/write or delete capabilities across all financial records stored by the application. The impact is significant for confidentiality and somewhat for integrity, while availability remains unaffected.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000 on Oracle platforms is affected. The advisory notes that the vulnerability could also extend to other Oracle products that interface with the same security components, though no specific additional products are listed.
Risk and Exploitability
The CVSS v3.1 base score is 8.5, indicating high severity. The EPSS score is below 1% (approximately 0.00316), showing a low but non‑zero probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, meaning no widespread exploitation has been reported. Attackers require only low privileges and can trigger the flaw without user interaction. The scope change in the vector implies that exploitation could also affect related products, broadening the potential impact.
OpenCVE Enrichment