Impact
An easily exploitable vulnerability in the deployment component of Oracle Hyperion Profitability and Cost Management allows a low privileged attacker with network access via HTTP to gain unauthorized access to critical data and perform insert, update, or delete operations. The impact includes a high confidentiality breach and a low integrity impact, as scored by a CVSS 3.1 Base Score of 7.1. Successful exploitation compromises the complete set of data accessible through the application and may enable further damage if additional layers of protection are not in place.
Affected Systems
Oracle Hyperion Profitability and Cost Management version 11.2.25.0.000 is the only affected release reported by the CNA. All installations of this version that expose the application over HTTP to the network are vulnerable.
Risk and Exploitability
The vulnerability is reachable remotely via HTTP, requires no user interface interaction, and only requires low privileged credentials. With an EPSS score of approximately 0.3% and not listed in the CISA KEV catalog, the CVSS score indicates a substantial risk. An attacker who can connect to the affected HTTP endpoint can immediately extract or alter sensitive business data, potentially leading to financial loss or regulatory non-compliance.
OpenCVE Enrichment