Oracle · Hyperion Financial Close Management · CVE-2020-2563
**Name of the Vulnerable Software and Affected Versions**
Oracle Hyperion Financial Close Management version 11.1.2.4
**Description**
The issue is related to insufficient access control in the Close Manager component, allowing a high-privileged attacker with network access via HTTP to compromise Hyperion Financial Close Management. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized creation, deletion, or modification access to critical data or all Hyperion Financial Close Management accessible data.
**Recommendations**
For version 11.1.2.4, consider restricting access to the Close Manager component to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the use of HTTP protocol for sensitive operations. At the moment, there is no information about a newer version that contains a fix for this vulnerability.