Impact
Oracle Hyperion Financial Reporting version 11.2.25.0.000 contains a server-side flaw that allows an unauthenticated attacker who can reach the HTTP interface to fully compromise the application. The flaw is easily exploitable, leading to complete loss of confidentiality, integrity, and availability, as reflected by a CVSS 3.1 base score of 9.8.
Affected Systems
Affected is Oracle Corporation’s Oracle Hyperion Financial Reporting product, specifically the 11.2.25.0.000 release. No other versions or additional vendors are listed in the official CNA data.
Risk and Exploitability
The vulnerability is exposed over the network via standard HTTP with no authentication required, making it highly feasible to attack. The CVSS score of 9.8 indicates critical severity; EPSS data is unavailable and the issue is not yet listed in CISA’s KEV catalog, but the combination of high impact and open attack vector strongly suggests immediate attention.
OpenCVE Enrichment