Impact
The vulnerability exposes a remote method invocation (RMI) endpoint that accepts connections without authentication, allowing an attacker to perform unauthorized creation, deletion or modification of critical data within Oracle Hyperion Financial Reporting. The lack of proper access control on the RMI interface results in high confidentiality and integrity impact, as reflected in its CVSS 3.1 Base Score of 9.1.
Affected Systems
The affected system is Oracle Hyperion Financial Reporting version 11.2.25.0.000, distributed by Oracle Corporation. This specific build is identified as vulnerable; no other versions or products are listed as impacted.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity, and the vulnerability can be exercised by any threat actor with network reach to the RMI port, requiring no credentials. The EPSS score of <1% suggests a low but non-zero probability of exploitation, while the lack of a KEV listing indicates no known large-scale attacks yet. Nevertheless, the flaw is straightforward to exploit, and an attacker could quickly gain unauthorized data modification capabilities via the unauthenticated RMI interface. The attack vector is through standard RMI network communication, presenting a large attack surface for unauthenticated actors.
OpenCVE Enrichment