Impact
The vulnerability enables a high‑privilege attacker with SQL network access to create, delete or modify critical data in Oracle Hyperion Financial Management. It is exploitable remotely via network‑based SQL interfaces, and the impact includes unauthorized data manipulation and full access to all Hyperion data. CVSS 3.1 score of 8.7 indicates high confidentiality and integrity impact. The weakness lies in the Security component and allows an attacker who already has elevated database privileges to expand their influence, potentially affecting additional related Oracle products. The flaw is essentially an authorization bypass that permits the attacker to perform operations normally restricted to certain roles.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000, a component of Oracle Corporation’s Hyperion suite, is affected. The Security component in this release is vulnerable and the scope change suggests that other connected Oracle products may also be impacted.
Risk and Exploitability
The CVSS base score of 8.7 indicates serious confidentiality and integrity compromise. However, the EPSS score is below 1 % and the vulnerability is not listed in CISA KEV, suggesting the current likelihood of exploitation is low. Attacks require network access to the Hyperion SQL endpoint and an account with high‑privilege rights. Once successful, the attacker can modify, delete, or capture any data that Hyperion manages and could extend influence to other partner Oracle products due to the noted scope change.
OpenCVE Enrichment