Impact
The vulnerability in Oracle Hyperion Financial Reporting allows an attacker with network access to the dedicated HTTP endpoint to read a subset of data that should be protected. The weakness allows read operations without authentication. Successful exploitation compromises confidentiality by exposing sensitive financial information.
Affected Systems
Oracle Hyperion Financial Reporting Server component, version 11.2.25.0.000, is affected.
Risk and Exploitability
The CVSS score of 5.3 categorizes this issue as medium severity. The EPSS score indicates a very low, but non‑zero, probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path requires an unauthenticated attacker reaching the Hyperion server over HTTP, after which the misconfigured access controls allow read‑only data retrieval.
OpenCVE Enrichment