Web-Based Report Designer Vulnerability in Oracle Hyperion Financial Reporting
CVE-2020-2769
2.4LOW
Summary
In Oracle Hyperion Financial Reporting, a vulnerability exists in the Web-Based Report Designer component that can be exploited by an attacker with high privileges and network access. This security flaw allows for unauthorized read access to certain subsets of data within Hyperion Financial Reporting, provided the attacker can induce human interaction from another individual. This vulnerability presents a risk to sensitive financial reporting data, making it essential for organizations to assess their exposure and implement appropriate security measures.
Affected Version(s)
Hyperion Financial Reporting 11.1.2.4
References
CVSS V3.1
Score:
2.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved