Impact
This vulnerability arises in the Security component of Hyperion Financial Management and allows an attacker with physical network access to the host to compromise the system without authentication. The flaw results in full takeover, exposing all data stored within Hyperion, and allowing uncontrolled modification or elimination of information. Confidentiality, integrity, and availability are all compromised, consistent with the CVSS 3.1 score of 8.8.
Affected Systems
Oracle Corporation’s Hyperion Financial Management, version 11.2.26.0.000, is impacted. No other versions or variants are listed as affected.
Risk and Exploitability
The CVSS vector indicates a local access requirement, not listed in the CISA KEV catalog and its EPSS score is less than 1%, suggesting limited publicly reported exploitation. However, the high severity score and the fact that any attacker who can join the physical communication segment can achieve full takeover means that the risk is significant and the potential impact for organizations operating Hyperion on a shared network or in a facility with untrusted personnel is high.
OpenCVE Enrichment