Impact
This vulnerability in Oracle Hyperion Financial Reporting allows an unauthenticated attacker with network access via HTTP to compromise the system. The flaw enables full takeover of the product, leading to confidentiality, integrity, and availability loss. The CVSS 3.1 base score of 8.1 reflects the high impact across all three core security dimensions.
Affected Systems
Affected product: Oracle Hyperion Financial Reporting from Oracle Corporation, version 11.2.25.0.000. No other versions or products are listed as impacted in the CNA data.
Risk and Exploitability
The vulnerability’s CVSS score indicates a high severity threat, and while the EPSS score is not reported, it is not listed in the CISA KEV catalog. The attack vector is inferred to be a network-based exploitation over HTTP, requiring no authentication, and the high attack complexity rating suggests the exploit is not trivial. Successful exploitation results in complete control of the Hyperion instance.
OpenCVE Enrichment