Impact
The vulnerability resides in the security component of Oracle Hyperion Financial Management and permits a local attacker who has logged onto the infrastructure where the application runs to take full control of the product. This compromise can expose confidential data, alter financial records, and disrupt the availability of the system. The low attack complexity and minimal privilege requirements detailed in the CVSS vector indicate that the flaw is highly exploitable once the attacker obtains local access.
Affected Systems
Affected is Oracle Corporation's Oracle Hyperion Financial Management, version 11.2.26.0.000, which is the only version reported as vulnerable.
Risk and Exploitability
With a CVSS v3.1 base score of 7.8, the vulnerability is considered high severity. The EPSS score of less than 1% suggests a low overall probability of exploitation in the wild, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack surface is local: any user who can log onto the underlying infrastructure can leverage the flaw. The combination of easy exploitation, significant impact, and the necessity of only local access creates a detectable risk for environments where the application is deployed.
OpenCVE Enrichment