Impact
The vulnerability resides in the Server component of Oracle Hyperion Financial Reporting 11.2.25.0.000. An attacker capable of reaching the system over HTTPS can authenticate as an anonymous user, bypassing normal access controls and gaining read‑only access to all reporting data. In addition, repeated requests can exhaust server resources, resulting in a partial denial of service. The flaw therefore threatens confidentiality and availability of the reporting platform.
Affected Systems
Oracle Hyperion Financial Reporting version 11.2.25.0.000 is the sole affected product according to the CNA data. No other versions or variants were listed as impacted.
Risk and Exploitability
The CVSS 3.1 base score of 8.2 classifies this flaw as high severity, with low attack complexity and no user interaction required. Although the EPSS score is currently unavailable, the combination of easy exploitation and unrestricted network exposure via HTTPS poses a significant risk. The vulnerability is not yet listed in the CISA KEV catalog, but its characteristics make it a likely target for automated exploitation.
OpenCVE Enrichment