Impact
The vulnerability is an access‑control flaw in Oracle Hyperion Financial Reporting version 11.2.25.0.000. It allows an attacker with low privileged credentials that can access the server via HTTPS to hijack the application. Successful exploitation results in full control of the server, permitting the attacker to read, modify, delete enterprise data, disrupt operations, and potentially more. The weakness is classified as improper authorization and authentication bypass (CWE‑284), leading to confidentiality, integrity, and availability loss.
Affected Systems
Oracle Hyperion Financial Reporting version 11.2.25.0.000 from Oracle Corporation. The vulnerability exists in the server component of that release. Only this version is listed as affected, with no known fixes for earlier or later releases.
Risk and Exploitability
The CVSS v3.1 base score is 8.8, indicating a high severity, with confidentiality, integrity and availability impacts. The EPSS score is less than 1 %, indicating a very low probability of exploitation at this time, yet the attack is possible over the network without user interaction and requires only low privileges to initiate. The vulnerability is not listed in CISA’s KEV catalog. Because the problem is an authorization bypass that can be triggered with any low‑privileged HTTPS session, the potential impact is severe enough to warrant immediate remediation.
OpenCVE Enrichment