Impact
A vulnerability in Oracle Hyperion Profitability and Cost Management allows an unauthenticated attacker to perform HTTP requests against the deployment component, granting unauthorized access to critical data. The weakness, identified as CWE-284 (Improper Access Control), is reflected in the CVSS vector as a high confidentiality impact (C:H) with network (AV:N) and low attack complexity (AC:L).
Affected Systems
Oracle Corporation’s Oracle Hyperion Profitability and Cost Management version 11.2.25.0.000 is affected. The vulnerability resides in the Deployment component and may allow impact on other Oracle Hyperion products.
Risk and Exploitability
The CVSS base score of 8.6 signifies a high severity vulnerability that can be exploited remotely without authentication. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, but the simple HTTP attack vector means that any network with access to the deployment interface can potentially compromise data confidentiality. Organizations should consider the risk high given the potential for unauthorized data exposure.
OpenCVE Enrichment