Impact
Vulnerability in Oracle Hyperion Financial Reporting allows an attacker to access the server without authentication over HTTP. Based on the description, it is inferred that an attacker might send a crafted request to the server’s vulnerable component to retrieve sensitive financial data, effectively bypassing the product’s access controls and resulting in a confidentiality breach.
Affected Systems
Affected is Oracle Hyperion Financial Reporting product version 11.2.25.0.000. Systems running this exact build are at risk; no other versions or components are listed as affected.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, with the vector implying a network‑based, low effort attack that requires no privileges. The EPSS score is less than 1%, indicating a low probability of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. Because an unauthenticated attacker can compromise the product over HTTP, if the system is exposed to the internet or internal network, adversaries have a straightforward attack path to compromise confidential data.
OpenCVE Enrichment