Impact
The vulnerability resides in the Repository component of Oracle Hyperion Financial Reporting. An attacker with only network connectivity to the HTTP service can exploit the flaw without authentication to perform unauthorized insert, update, or delete operations on the application data and read protected information. The weakness is classified as CWE-306, indicating an authentication bypass vulnerability. The impact on confidentiality is moderate and on integrity is moderate, as the attacker can both introduce harmful data and modify existing records.
Affected Systems
Oracle Corporation’s Hyperion Financial Reporting, version 11.2.25.0.000 is the only version explicitly listed as affected. No other product or version information is provided.
Risk and Exploitability
The CVSS base score of 6.5 reflects moderate severity with low attack complexity, no authentication, no user interaction, and a shared scope, impacting confidentiality and integrity. The EPSS score is less than 1%, indicating a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog, suggesting no active exploitation. The likely attack vector is unauthenticated HTTP access to the Enterprise Hyperion Financial Reporting Repository component, enabling an attacker to modify, insert, delete, or read data without credentials.
OpenCVE Enrichment