Impact
This vulnerability in Oracle Hyperion Financial Reporting enables an unauthenticated attacker who can reach the system over HTTP to create, delete, or modify critical data, or to gain unauthorized access to all reportable data. The weakness resides in the server component, allowing compromised confidentiality and integrity but not availability. The stated CVSS 3.1 base score of 6.8 reflects these impacts.
Affected Systems
Oracle Corporation’s Oracle Hyperion Financial Reporting product, version 11.2.25.0.000, is affected. This applies to all installations of this version that still use the affected server component and expose an HTTP interface to the network.
Risk and Exploitability
The attack path requires network access to the HTTP port and human interaction from a user other than the attacker. The EPSS score is not available, indicating insufficient data to assess current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Although the CVSS score is moderate, the potential for unauthorized modification or disclosure of sensitive financial data makes the issue significant for organizations relying on this product. If patches are not applied, a compromised device could provide an attacker with broad access to key financial information.
OpenCVE Enrichment