Impact
The vulnerability exists in the Deployment component of Oracle Hyperion Profitability and Cost Management and allows an attacker who can reach the system via HTTP and possesses high privileges to gain full control of the application. Successful exploitation leads to compromise of confidentiality, integrity, and availability, effectively taking over the service. The weakness is identified as improper access control and weak permissions management, which enable privileged users to bypass critical security checks.
Affected Systems
Oracle Corporation's Hyperion Profitability and Cost Management product, version 11.2.25.0.000, is affected. No other vendors, products, or versions are identified in the CVE listing.
Risk and Exploitability
The CVSS 3.1 base score of 7.2 reflects high severity with impacts on confidentiality, integrity, and availability. The attack vector indicates network access (AV:N), low complexity (AC:L), and high privileges (PR:H), meaning an attacker with the appropriate credentials can fully compromise the application. The EPSS score of less than 1% suggests that widespread exploitation is unlikely at this time, and the vulnerability is not listed in the CISA KEV catalog, so no mandated actions are required by CISA.
OpenCVE Enrichment