Impact
The issue is an authentication and access control flaw that allows low‑privileged users with HTTP access to obtain confidential data and, in some cases, modify it. The flaw resides in the Server component of Oracle Hyperion Financial Reporting 11.2.25.0.000. Because the vulnerability is readily exploitable, an adversary can gain unauthorized read and possibly write access to the reporting database, exposing sensitive financial information.
Affected Systems
The vulnerable software is Oracle Hyperion Financial Reporting, version 11.2.25.0.000. All installations of this product running the affected server component are susceptible. No other versions were indicated as affected.
Risk and Exploitability
The CVSS base score of 6.3 reflects moderate confidentiality impact and low integrity impact. There is no EPSS score, and the issue is not cataloged in KEV. Attackers require network connectivity to the HTTP interface and a user interface interaction from a party other than the attacker. The vectors suggest a network‑based exploitation in an environment where HTTP traffic is accessible to potential attackers. The lack of automated exploitation evidence makes the likelihood lower, yet the reach granted is significant, warranting timely remediation.
OpenCVE Enrichment