Impact
This vulnerability allows an unauthenticated attacker to access Oracle Hyperion Financial Reporting over the network via HTTP. The flaw enables the attacker to read or modify critical financial data without requiring credentials, compromising confidentiality. The weakness is an improper access control that permits full disclosure of all data accessible through the Hyperion interface.
Affected Systems
The affected product is Oracle Hyperion Financial Reporting, version 11.2.25.0.000, which is the only supported release indicated as vulnerable. The flaw resides in the server component of the Hyperion application.
Risk and Exploitability
The CVSS base score of 7.5 classifies this as a medium‑to‑high severity vulnerability; the vector indicates network-only access with a low attack complexity and no user interaction. While a current EPSS score is not reported, the lack of obfuscation and the direct HTTP entry point suggest that exploitation could be attempted by attackers with minimal effort. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation yet but the potential impact remains significant for data confidentiality.
OpenCVE Enrichment