Impact
Vulnerability in Oracle Hyperion Financial Management allows a low‑privileged attacker with network access to execute SQL commands that can compromise the application, potentially leading to a full takeover. The flaw, identified in component Security of version 11.2.26.0.000, is easily exploitable and grants an attacker the ability to read, modify, or delete confidential data and disrupt service availability. The impact spans confidentiality, integrity, and availability, effectively giving the attacker control over the entire Hyperion instance.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000, as supplied by Oracle Corporation.
Risk and Exploitability
CVSS base score of 8.8 indicates high severity. EPSS score is below 1 %, suggesting that, while the vulnerability is simple to exploit, current exploitation evidence is scarce. The vulnerability is not listed in CISA KEV. Attackers can reach the affected system over the network and leverage SQL interfaces that are accessible to low‑privileged users, making exploitation straightforward. The exploit does not alter the affected components’ scope, remaining confined to the Hyperion instance, but the consequences are full takeover once the flaw is exploited.
OpenCVE Enrichment