Impact
An unauthenticated attacker with network access over HTTPS can exploit a flaw in the Oracle Hyperion Financial Reporting Server component to gain unauthorized access to all reporting data or selectively obtain critical information. In addition to data exposure, repeated or sustained attacks can exhaust server resources, causing a partial denial of service that would degrade availability for legitimate users.
Affected Systems
The Oracle Hyperion Financial Reporting product, version 11.2.25.0.000, is the sole affected release per the CNA data. No other versions or editions are listed as impacted.
Risk and Exploitability
The CVSS v3.1 base score of 8.2 signifies high severity, with low attack complexity and no user interaction required. The EPSS score of less than 1% indicates a low current exploitation probability, yet the vulnerability is network‑exposed via HTTPS and is easily exploitable, presenting a significant risk. The flaw is not yet listed in the CISA KEV catalog, but its characteristics suggest it could be a target for automated exploitation.
OpenCVE Enrichment