Impact
This vulnerability allows an unauthenticated attacker to access Oracle Hyperion Financial Reporting over the network via HTTP. The flaw enables the attacker to read or modify critical financial data without requiring credentials, compromising confidentiality. The weakness is an improper access control that permits full disclosure of all data accessible through the Hyperion interface.
Affected Systems
The affected product is Oracle Hyperion Financial Reporting, version 11.2.25.0.000, which is the only supported release indicated as vulnerable. The flaw resides in the server component of the Hyperion application.
Risk and Exploitability
The CVSS base score of 7.5 classifies this as a medium-to-high severity vulnerability; the vector indicates network-only access with a low attack complexity and no user interaction. With an EPSS score of 0.00377 (≈0.38%), the probability of exploitation is very low, yet the direct HTTP entry point suggests that exploitation could be attempted by attackers with minimal effort. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation yet but the potential impact remains significant for data confidentiality.
OpenCVE Enrichment