Impact
Enterprise users deploying Oracle Hyperion Profitability and Cost Management may be exposed to unauthorized data disclosure. The flaw resides in the Deployment component and allows a low‑privileged network attacker with HTTP access to gain unauthorized read access to all restricted data, effectively bypassing the intended data‑access controls. The vulnerability’s impact is confined to confidentiality, as indicated by its CVSS vector, but the potential scale of data exposure could be significant if the attack is successful.
Affected Systems
Oracle Corporation’s Hyperion Profitability and Cost Management version 11.2.25.0.000 is the only version listed as affected. The product is typically accessed over HTTP, and the advisory does not mention other component versions.
Risk and Exploitability
The CVSS base score of 7.7 points to a high‑severity vulnerability that is moderately easy to exploit. The EPSS score of less than 1% indicates a low current exploitation probability, yet the advisory describes the flaw as “easily exploitable”, implying that an attacker could perform the attack with minimal technical effort via standard HTTP requests. The fact that the issue is listed as impacting additional products indicates a broader scope, heightening the risk for organizations that may have integrated or rely on other Hyperion components. The vulnerability is not in the CISA KEV catalog, but its high confidentiality impact warrants immediate attention.
OpenCVE Enrichment