Impact
A vulnerability in Oracle Hyperion Financial Reporting 11.2.25.0.000 allows an unauthenticated attacker with network access via HTTP to achieve a full system takeover, resulting in complete compromise of confidentiality, integrity, and availability. The CVSS 3.1 base score of 8.1 reflects these severe impacts.
Affected Systems
Oracle Corporation’s Hyperion Financial Reporting product, version 11.2.25.0.000, is affected. No other versions or components are currently listed as vulnerable.
Risk and Exploitability
The vulnerability can be exploited remotely over HTTP without authentication or special privileges. While the EPSS score is not available, the high CVSS score indicates significant risk, and the absence of a KEV listing does not lower the potential threat. Attackers could send crafted HTTP requests to the server to trigger code execution and gain full control of the application server.
OpenCVE Enrichment