Impact
The vulnerability in Oracle Hyperion Financial Reporting allows an attacker with network access to the dedicated HTTP endpoint to read a subset of data that should be protected. The weakness is a form of improper access control that permits read operations without authentication. Successful exploitation compromises confidentiality by exposing sensitive financial information.
Affected Systems
Oracle Hyperion Financial Reporting version 11.2.25.0.000 is affected. This applies to the Server component of the product.
Risk and Exploitability
The CVSS score of 5.3 places this issue in the medium severity range. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. The likely attack path requires an unauthenticated attacker to reach the Hyperion server over HTTP, after which the misconfigured access controls allow read‑only data retrieval.
OpenCVE Enrichment