Impact
The vulnerability is a SQL injection flaw found in the Security component of Oracle Hyperion Financial Management. An attacker who can reach the database and possesses high database privileges can insert malicious SQL. The application forwards the injected statements directly to the database, allowing the attacker to read, modify, or delete any data. Depending on the scope of the gained privileges, the attacker could ultimately compromise the entire Hyperion application, breaking confidentiality, integrity, and availability.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000 is affected. Earlier or later releases are not reported as vulnerable in the available data.
Risk and Exploitability
The CVSS 3.1 base score of 7.2 reflects high severity and full impact on confidentiality, integrity, and availability. The EPSS score of less than 1 % indicates a low probability of exploitation at the time of this assessment, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network access to the database, requiring the attacker to have high‑privilege credentials. The description indicates that successful exploitation can lead to a complete takeover of the Hyperion application.
OpenCVE Enrichment