Impact
A vulnerability in Oracle Hyperion Financial Reporting allows an unauthenticated attacker with network access via HTTP to compromise the system. The flaw enables the attacker to perform unauthorized updates, inserts, or deletions, as well as read a subset of the data accessible through the application, according to the CVSS vector indicating a low confidentiality and integrity impact but no availability impact. As the description states, successful exploitation requires human interaction from a user other than the attacker, meaning the attacker must persuade or trick a legitimate user into facilitating the attack. The overall CVSS 3.1 base score of 5.4 reflects a moderate severity that still poses a significant risk to the confidentiality and integrity of financial reporting data.
Affected Systems
Oracle Hyperion Financial Reporting version 11.2.25.0.000 is affected. This is the only version identified in the CNA's reported affected-version list and corresponds to the component labeled Server.
Risk and Exploitability
The attack vector is inferred to be over the network, specifically HTTP, as the vulnerability is described as "via HTTP". The CVSS score of 5.4 indicates a moderate risk level, and no EPSS score is available, making it difficult to gauge current exploit probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, so there is no documented active exploitation at the time of analysis. An attacker with unauthenticated network access who coaxes a legitimate user into interacting with the system could gain unauthorized data modification or read capabilities, potentially compromising financial reporting integrity and confidentiality. The lack of availability impact means the system itself remains operational, but data integrity and privacy are at risk.
OpenCVE Enrichment