Impact
An authentication and access‑control flaw in the Server component of Oracle Hyperion Financial Reporting 11.2.25.0.000 allows a low‑privileged attacker with network access via HTTP to obtain confidential reporting data and, in some cases, modify it. The vulnerability can lead to high confidentiality compromise and low integrity impact, enabling read or write access to sensitive financial information without valid credentials.
Affected Systems
Oracle Hyperion Financial Reporting version 11.2.25.0.000. All installations running the affected Server component are susceptible; no other versions are mentioned as impacted.
Risk and Exploitability
The CVSS base score of 6.3 indicates moderate confidentiality impact and low integrity impact. The EPSS score of < 1% reflects an extremely low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers need network connectivity to the exposed HTTP interface and the cooperation of a user other than the attacker, suggesting a network‑based exploitation path with user interaction required. Given the potential for unauthorized data access and modification, timely remediation is recommended.
OpenCVE Enrichment