SQL Injection Vulnerability in Oracle Hyperion Financial Reporting
CVE-2017-10358
6.4MEDIUM
What is CVE-2017-10358?
A vulnerability exists in the Oracle Hyperion Financial Reporting component that allows low privileged attackers with network access via HTTP to exploit the system. This can lead to unauthorized access, permitting both data modification and extraction. Such attacks can compromise not only the Financial Reporting aspect but also potentially affect other related products. Attackers can execute unauthorized actions such as inserting, updating, or deleting accessible data, along with gaining read access to certain data within Oracle Hyperion Financial Reporting.
Affected Version(s)
Hyperion Financial Reporting 11.1.2