Impact
This vulnerability exists in the Oracle Hyperion Profitability and Cost Management product. An unauthenticated attacker with network access via HTTP can create, delete, or modify critical data, resulting in full unauthorized access to all data accessible by the application. The flaw therefore threatens both confidentiality and integrity of the data but does not impact availability.
Affected Systems
Oracle Corporation's Hyperion Profitability and Cost Management version 11.2.25.0.000 is affected. No other versions or products are listed as impacted. The deployment component of this product is specifically vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 indicates a high severity remote vulnerability. Because it is exploitable with no required authentication and can be triggered over standard HTTP, the likelihood of successful attacks is significant. The EPSS score of 0.00398 (less than 1%) indicates a very low exploitation probability, and a listing in CISA's KEV catalog is not present, but the high CVSS and straightforward attack vector still make this a critical risk for organizations running the affected product.
OpenCVE Enrichment