Impact
A local vulnerability in Oracle Hyperion Financial Management 11.2.26.0.000 allows an attacker who can log onto the underlying infrastructure to create, delete, or modify data. The flaw is exploitable by a low‑privileged user and provides high confidentiality and integrity impact, with an AV:L, AC:L, PR:L, UI:N vector in the CVSS 3.1 score of 8.4. Successful exploitation results in unauthorized access to all data accessible through Hyperion, as well as the ability to alter or delete critical information.
Affected Systems
Oracle Corporation’s Hyperion Financial Management application, version 11.2.26.0.000, is directly impacted. No other versions or products are listed as affected in the CNA data, but the scope‑changing nature implies that compliance components that rely on Hyperion data may also be vulnerable.
Risk and Exploitability
The CVSS base score of 8.4 indicates a high‑severity vulnerability with local exploitation. The EPSS score of less than 1 % suggests that, at the time of analysis, the likelihood of exploitation is low but not negligible. The vulnerability is not currently listed in the CISA KEV catalogue, so no known critical exploits have been reported. Attackers would need local access to the Hyperion host; thus the attack vector is most likely local, although the scope change indicates potential for lateral movement to other system components if the attacker gains additional privileges.
OpenCVE Enrichment