Impact
An unauthenticated attacker with access to the physical network segment that connects to the hardware running Oracle Hyperion Financial Management can exploit a flaw in the Security component. The vulnerability allows the attacker to create, delete, or modify critical data or obtain complete access to all data managed by the application. The CVSS 3.1 base score of 8.1 reflects high confidentiality and integrity impacts, and the issue is classified under CWE-284 (Improper Access Control).
Affected Systems
Oracle Hyperion Financial Management, version 11.2.26.0.000, delivered by Oracle Corporation.
Risk and Exploitability
The CVSS score of 8.1 and the EPSS score of less than 1% indicate a high severity, though low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local network (AV:A), meaning an attacker must have physical proximity or network access to the server’s hardware. No special conditions beyond physical test site access are required, so the risk to environments with exposed physical infrastructure is significant.
OpenCVE Enrichment