Impact
A flaw in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000 allows an unauthenticated attacker with network SQL access to perform SQL injection. The defect is due to improper handling of untrusted SQL input, matching CWE‑89. Once the injection succeeds, the attacker can issue arbitrary SQL statements, read or modify financial data, and ultimately compromise confidentiality, integrity, and availability of the entire Hyperion application.
Affected Systems
Oracle Corporation’s Hyperion Financial Management product, specifically version 11.2.26.0.000, is affected. No other versions were reported in this CVE.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 labels the vulnerability as Critical, indicating that any successful exploitation would result in complete control of the system. The EPSS score is below 1 percent, suggesting that exploitation is currently rare, but the severity remains high. The flaw can be triggered over the network via SQL; an attacker with network access to the Hyperion database or application interface can exploit the SQL injection with minimal effort. The vulnerability is not listed in CISA’s KEV catalog, but the high severity warrants prompt remediation.
OpenCVE Enrichment