Impact
The vulnerability is located in the Security component of Oracle Hyperion Financial Management and permits an unauthenticated attacker who has physical access to the hardware to create, delete, or modify critical data, as well as read any data that the system stores. This results in a direct breach of confidentiality and integrity, exposing sensitive financial information and enabling data tampering without requiring any role‑based credentials. The weakness is inferred to be an improper access control flaw that allows unauthorized data operations.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000 is affected by this flaw.
Risk and Exploitability
The CVSS base score of 8.1 indicates a high impact scenario, while the EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. Attack execution requires the attacker to be physically present at the machine or to have direct hardware access, which limits the threat to insiders or opportunistic actors but still provides a straightforward path to compromise the entire financial data set. Because the exploit is easily exploitable locally with no authentication, the risk remains high until the patch is applied.
OpenCVE Enrichment