Impact
A vulnerability in Oracle Hyperion Financial Management version 11.2.26.0.000 allows a high‑privileged attacker who can reach the system over Oracle Net to compromise the application. Successful exploitation can result in full takeover of the target instance, leading to loss of confidentiality, integrity, and availability of the financial data. The CVSS 3.1 base score of 9.1 indicates a critical rating, and the vector AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H shows that normal users or the public can initiate the attack, that the attacker only needs low effort, requires high privileges after compromise, and that the vulnerability changes scope to affect other components or products.
Affected Systems
Oracle Corporation’s Hyperion Financial Management application, specifically the 11.2.26.0.000 release. Only this version is listed as affected, but the description notes that attacks may have a broader impact on additional products due to a scope change.
Risk and Exploitability
The critical CVSS score signals a severe risk, while the EPSS < 1 % indicates that exploitation is currently unlikely, although the possibility of future exploitation cannot be dismissed. The vulnerability is not listed in the CISA KEV catalog, yet the combination of an easily exploitable network entry point, high privileges required, and the complete takeover potential warrants serious attention. An attacker would need network access to Oracle Net and sufficient privileges to execute the exploit, after which they could gain full control of the Hyperion system and any integrated components.
OpenCVE Enrichment