Impact
A local vulnerability in the Security component of Oracle Hyperion Financial Management allows an unauthenticated attacker with physical access to the hardware to compromise the application. Successful exploitation can cause a denial‑of‑service through repeated crashes and provides the attacker the ability to update, insert, or delete data that should be protected. The flaw is scored 7.1 on the CVSS 3.1 scale, reflecting moderate severity and impacts on integrity and availability. It is a classic access‑control weakness (CWE‑284).
Affected Systems
The vulnerability affects Oracle Corporation’s Hyperion Financial Management version 11.2.26.0.000. No other versions are currently listed as impacted. Only the specified product and build are susceptible to the flaw.
Risk and Exploitability
The flaw is exploitable only when an attacker can reach the server physically, as the access vector is local. With the EPSS score below 1 % and the lack of a KEV listing, the probability of widespread, automated exploitation remains low. Nonetheless, organizations that host the application in environments with open or insufficient physical security face potential downtime and inadvertent or intentional data modification. The CVSS 3.1 Base Score of 7.1 indicates moderate severity, affecting integrity and availability.
OpenCVE Enrichment