Impact
A flaw in the security component of Oracle Hyperion Financial Management allows a user who can log into the host machine to elevate privileges and gain full control of the application. This local privilege escalation can result in the attacker having read, modify, or delete all financial data, disrupting availability and compromising confidentiality and integrity of the information stored by Hyperion. The weakness stems from improper privilege management and broken access control, as identified by CWE‑269, CWE‑272, and CWE‑285.
Affected Systems
Oracle Hyperion Financial Management, version 11.2.26.0.000, is the only version validated to contain the vulnerability.
Risk and Exploitability
The CVSS 3.1 score of 6.7 indicates moderate severity. The EPSS score of less than 1 % and absence from the CISA KEV catalog suggest that exploitation is unlikely but still possible. An attacker needs local high privileged access to the server hosting Hyperion; once this precondition is met, the vulnerability can be leveraged to take over the application and thereby compromise all associated financial processes.
OpenCVE Enrichment