Impact
An exploitable flaw in the security component of Oracle Hyperion Financial Management allows a network attacker with high privileges to take full control of the system. Success can compromise confidentiality, integrity and availability of the application, potentially leading to a complete takeover of the affected instance. The weakness aligns with improper privilege management and unauthorized access controls.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000 is affected. The vulnerability resides in the security component and may impact other Oracle Hyperion products because the attack escalates privileges and modifies application state.
Risk and Exploitability
The CVSS score of 9.1 points to a critical severity. The EPSS score of <1% suggests that while exploitation is not widespread, the vulnerability remains worth addressing promptly. The fact that it is not in the KEV catalog does not reduce the need for mitigation, as the potential for compromise is extreme and would likely affect any environment where the vulnerable product is deployed. The attack likely proceeds via network-based HTTP requests that exploit the flawed access control, requiring a high‑privilege attacker to gain control, and may also extend to additional products due to scope change.
OpenCVE Enrichment