Impact
This vulnerability resides in the Security component of Oracle Hyperion Financial Management and allows an unauthenticated attacker who can reach the same physical communication segment to create, delete, or modify critical financial data and to trigger a denial‑of‑service condition by repeatedly crashing the application. The flaw provides no compromise of confidentiality but imposes a high impact on data integrity and availability, as reflected in a CVSS 3.1 base score of 8.1.
Affected Systems
Affected product is Oracle Hyperion Financial Management version 11.2.26.0.000, sold by Oracle Corporation. No other Oracle or non‑Oracle products are identified as vulnerable in the published advisory.
Risk and Exploitability
The flaw carries a CVSS score of 8.1, indicating high severity, while the EPSS score is below 1 %, suggesting that exploitation is unlikely but not impossible. The advertised attack vector is physical or adjacent network access (AV:A); no authentication or user interaction is required, so the vulnerability is exploitable from within the same local network or from a compromised adjacent network segment. The risk is therefore largely confined to internal threats or compromised network infrastructure and the issue is not listed in the CISA KEV catalog.
OpenCVE Enrichment