Impact
The vulnerability is located in the Deployment component of Oracle Hyperion Profitability and Cost Management and can be exploited by a low‑privileged attacker who can reach the system over HTTP. A successful attack allows the attacker to read critical data, gain full access to all data stored in the application, and can trigger a partial denial of service. The weakness is reflected in CWE‑284, indicating improper access control.
Affected Systems
The issue affects Oracle Corporation’s Hyperion Profitability and Cost Management product, version 11.2.25.0.000.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 denotes moderate to high severity, with high confidentiality impact and low availability impact. The EPSS score is < 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed public exploitation yet. However, because the attack can be carried out by a low‑privileged user over HTTP, the risk remains significant, warranting prompt remediation.
OpenCVE Enrichment