Impact
A vulnerability in Oracle Hyperion Financial Management allows an attacker without authentication to create, delete, or modify critical data through network access via SSH. This flaw can lead to unauthorized changes to all data exposed by the application, severely compromising its confidentiality and integrity. The weakness is based on improper access control that enables unauthenticated data manipulation.
Affected Systems
The affected product is Oracle Hyperion Financial Management version 11.2.26.0.000, as supplied by Oracle Corporation. Only this specific release is known to be vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 7.4 indicates significant potential for data integrity impact, though the availability impact remains minimal. The EPSS score of less than 1% suggests exploitation is unlikely at present, and the vulnerability is not listed in CISA KEV. An attacker would need network-level access and the ability to establish an SSH session, after which the flaw permits unauthorized data manipulation. No known public exploit or mitigation is documented beyond the vendor advisory.
OpenCVE Enrichment