Impact
The vulnerability exists in the Security component of Oracle Hyperion Financial Management 11.2.26.0.000, representing a broken access control weakness (CWE-284). An attacker who can communicate over the physical network segment attached to the hardware where the application runs can exploit the flaw without authentication or privileges. Successful exploitation permits the attacker to create, delete, or alter critical data, and it may provide full access to all data the application can reach. This results in significant confidentiality and integrity damage to the system's data, and the scope change indicates that the compromise could extend to other affected products.
Affected Systems
Only Oracle Hyperion Financial Management 11.2.26.0.000 is listed as affected. The vendor is Oracle Corporation, and the product affected is Hyperion Financial Management. Users deploying this specific release should assess whether they are using the affected version and plan remediation accordingly.
Risk and Exploitability
The CVSS v3.1 base score of 8.0 signals a high severity vulnerability. The EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The required attack vector is local: the attacker must be able to reach the physical communication segment attached to the Hyperion servers, with no privilege elevation or user interaction needed. Once accessed, the scope change permits broader impact across the environment.
OpenCVE Enrichment