Impact
A vulnerability in Oracle Hyperion Profitability and Cost Management allows an attacker with low privileges and network access via HTTP to create, delete, or modify critical data, or gain complete access to all accessible data. The weakness arises from insufficient access controls, allowing unauthorized operations that affect both confidentiality and integrity of the system’s data. The flaw is exploitable without user interaction, and can be leveraged by a local or remote attacker who can reach the application over the network.
Affected Systems
The affected product is Oracle Hyperion Profitability and Cost Management version 11.2.25.0.000. This is the only documented affected release for this vulnerability.
Risk and Exploitability
The CVSS v3.1 score of 8.1 indicates high severity, with network-based access, low attack complexity, and low attacker privileges required. The EPSS score of less than 1% indicates a very low probability of exploitation, although the high impact remains. The vulnerability can be exploited over HTTP, requiring only network connectivity to the affected instance; as a result, users in permissive network environments are vulnerable.
OpenCVE Enrichment