Impact
A flaw was identified in Oracle Hyperion Financial Reporting Server version 11.2.25.0.000 that allows an attacker who can reach the service over HTTP to compromise the server without prior authentication. The vulnerability yields full control over the application, permitting the attacker to execute arbitrary code. Though the CVE entry does not explicitly list weakness categories, the description of unauthenticated takeover indicates authentication bypass and unauthorized access, which corresponds to CWE-287 (Improper Authentication) and CWE-284 (Improper Authorization). The CVSS 3.1 base score of 9.8 highlights a critical impact on confidentiality, integrity, and availability.
Affected Systems
Oracle Corporation’s Hyperion Financial Reporting product, server component version 11.2.25.0.000, is affected. No other product or version information is available in the CVE data.
Risk and Exploitability
The CVSS assessment of 9.8 signals substantial severity, and the EPSS score of <1% indicates a low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Because the entry states that an unauthenticated attacker can exploit the weakness from any network location that can contact the application’s HTTP interface, the attack vector is clear and the path to exploitation is straightforward for remote adversaries.
OpenCVE Enrichment