Impact
A flaw in Oracle Hyperion Financial Management allows an unauthenticated attacker with network access to send SQL commands to the application, enabling creation, deletion, or modification of critical data without authorization. The weakness combines an access control failure with SQL injection capability, leading to loss of data confidentiality and integrity.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000 from Oracle Corporation is the only affected product listed. No other vendor or product versions are noted in the available data.
Risk and Exploitability
The CVSS 3.1 base score of 7.4 shows a high severity with significant confidentiality and integrity impact. The EPSS score of < 1% indicates the current likelihood of exploitation is low, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would need network reach to the Hyperion application or underlying database and craft SQL statements to exploit the flaw, but no authentication is required.
OpenCVE Enrichment