Impact
The flaw resides in the Security component of Oracle Hyperion Financial Management. If an attacker has local access to the host running the application with high privileges, they can trigger the vulnerability, but an additional user interaction from a person other than the attacker is required. Successful exploitation can lead to takeover of the Hyperion service, and based on the CVSS vector (Confidentiality, Integrity, Availability impacts), it is inferred that sensitive financial data could be exposed, integrity could be compromised, and availability may be affected.
Affected Systems
Oracle Hyperion Financial Management 11.2.26.0.000 is the affected product. The vulnerability impacts only this specific version; no other Oracle products are listed as affected by the CNA. It also notes that attacks against this product may spill over to other components, signalling a scope change.
Risk and Exploitability
The CVSS base score is 7.7, with local access, low attack complexity, high privileges, user interaction, and a scope change. The EPSS score is less than 1%, indicating low likelihood of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The threat primarily exists in environments where privileged credentials are not tightly controlled and legitimate users perform actions that allow the vulnerability to be triggered. An adversary could use the vulnerability during routine maintenance or from a compromised administrative account to elevate capabilities and manipulate financial data.
OpenCVE Enrichment