Impact
Oracle Hyperion Financial Reporting version 11.2.25.0.000 contains a server‑side access‑control flaw that permits an unauthenticated attacker with network access via HTTP to take full control of the application, compromising confidentiality, integrity, and availability. Based on the description, it is inferred that an attacker can execute arbitrary code on the server; the vulnerability is classified as CWE‑284 (Improper Access Control).
Affected Systems
The affected product is Oracle Corporation’s Hyperion Financial Reporting server, specifically release 11.2.25.0.000. No other vendors, products, or versions are listed in the CNA data, so the risk is confined to this version and component.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 indicates critical severity; the network‑based attack requires only unauthenticated HTTP access, making exploitation trivially achievable in theory. The EPSS score of < 1% suggests a low current exploitation probability, and the vulnerability is not yet listed in CISA’s KEV catalog. Nevertheless, the combination of a high impact, open attack vector and absence of authentication warrants immediate action.
OpenCVE Enrichment