Impact
The vulnerability in Oracle Hyperion Financial Reporting permits an unauthenticated attacker to target the reporting server over HTTP. An exploitation attempt can lead to unauthorized update, insert, or delete operations on financial data, as well as read access to restricted data subsets. However, the attacker must obtain human interaction from a third party—such as a user who initiates or completes a request—to successfully exploit the flaw, meaning the attack cannot proceed solely through automated network traffic.
Affected Systems
Oracle Corporation’s Hyperion Financial Reporting version 11.2.25.0.000 is affected. No other versions or products are listed, but the description notes that attacks may also impact additional components if configured with the same server.
Risk and Exploitability
The CVSS v3.1 base score of 6.1 indicates moderate severity. The attack vector is network-based (HTTP) and requires human interaction from a third party to complete the exploit. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no known large‑scale exploitation. Nevertheless, the potential for unauthorized data modification and disclosure poses a significant risk to organizations relying on Hyperion Financial Reporting for financial data integrity.
OpenCVE Enrichment