Impact
The vulnerability exists in the server component of Oracle Hyperion Financial Reporting, where an unauthenticated attacker can send crafted HTTP requests that enable unauthorized creation, modification, or deletion of critical data and full access to all accessible data. This represents a breach of confidentiality and integrity and is a CWE‑284 (Improper Access Control) weakness.
Affected Systems
Oracle Corporation’s Hyperion Financial Reporting, version 11.2.25.0.000, is the only known affected release. Deployments of the server component that have not been patched beyond this version are at risk.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 indicates high severity, and the EPSS score of 0.352% indicates low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack requires network access over HTTP without authentication, but also requires a human interaction from a user other than the attacker, limiting the attacker’s ability to exploit the flaw solo. Environments that expose the Hyperion server to the internet or rely on shared user credentials face a high risk.
OpenCVE Enrichment