Impact
A flaw in Oracle Hyperion Financial Reporting version 11.2.25.0.000 permits an unauthenticated attacker with network access via HTTP to perform a remote takeover of the application. The vulnerability is a code execution flaw that can lead to complete compromise of confidentiality, integrity, and availability.
Affected Systems
Oracle Corporation’s Hyperion Financial Reporting product, specifically version 11.2.25.0.000, is vulnerable. No other versions or components are currently listed as affected.
Risk and Exploitability
The issue can be exploited remotely over HTTP without authentication and without special privileges. The CVSS 3.1 base score of 8.1 reflects severe impact, while the EPSS score of less than 1% indicates a low probability of exploitation. It is not listed in CISA KEV. Attackers can send crafted HTTP requests to trigger execution of arbitrary code on the server, resulting in a full system takeover.
OpenCVE Enrichment