Impact
The vulnerability lies in the can be exploited by an attacker who has local, physical access to the network segment attached to the hardware. The flaw allows the attacker to bypass authentication checks, enabling unauthorized creation, deletion, modification of critical data and granting full read access to all data stored by the application. As a result, confidentiality, integrity and (to a lesser extent) availability of the application’s data are compromised, potentially triggering a partial denial of service.
Affected Systems
This issue affects Oracle Hyperion Financial Management version 11.2.26.0.000. No other versions or related products are listed as impacted.
Risk and Exploitability
The CVSS v3.1 score of 8.3 indicates a high severity assessment, but the EPSS score of less than 1% shows that the exploitation probability is currently very low. The vulnerability is not yet listed in the CISA KEV catalog. Because the attack requires physical or local network access (AV:A) and no local. Without a public exploit, the overall risk is high for organizations that expose the application to potential local actors, but the chance of successful exploitation in the wider threat landscape is low.
OpenCVE Enrichment