Impact
The vulnerability allows an attacker who can contact the system over HTTP to compromise the Oracle Hyperion Financial Reporting server without any prior authentication. Once exploited the attacker can take full control of the application, resulting in loss of confidentiality, integrity, and availability of all data processed by the reporting system.
Affected Systems
Oracle Corporation’s Hyperion Financial Reporting product version 11.2.25.0.000 is affected. No other product or version information is provided.
Risk and Exploitability
The CVSS 3.1 score of 9.8 indicates a critical severity with full confidentiality, integrity, and availability impacts. The EPSS score is not available and the vulnerability is not listed in CISA KEV. Because the attack vector stated is network HTTP and no authentication is required, the path is highly likely to be exploitable by remote adversaries who can reach the application’s HTTP interface.
OpenCVE Enrichment