Impact
A vulnerability in the security component of Oracle Hyperion Financial Management allows a low-privileged attacker who can reach the application over the network to exploit SQL injection flaws that can lead to a full takeover of the application, impacting confidentiality, integrity and availability. The vulnerability is rated CVSS 3.1 score 8.8, indicating high severity.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000 is affected. This release was identified as vulnerable to the described SQL injection in the security component.
Risk and Exploitability
The risk is high, with a CVSS base score of 8.8, but the EPSS indicates a very low exploitation probability (under 1%). The vulnerability is not listed in CISA’s KEV catalog. Attack likely requires network access to the application and a low-privileged account that can submit SQL queries; the vector is network (AV:N) with low complexity. Because the flaw is a classic injection, a determined adversary can achieve full compromise if the conditions are met.
OpenCVE Enrichment