Impact
A vulnerability exists in the Oracle Hyperion Financial Reporting server component that permits an unauthenticated attacker to send HTTP requests to the application. The flaw requires human interaction from a third party to trigger the attack, but once activated it enables the attacker to modify, insert or delete data and to read portions of the system’s information, thereby compromising both data integrity and confidentiality.
Affected Systems
Oracle Corporation’s Hyperion Financial Reporting, version 11.2.25.0.000.
Risk and Exploitability
The CVSS v3.1 base score of 5.4 indicates moderate risk. The EPSS score is 0.00238, showing a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is unauthenticated network traffic over HTTP, but the need for user interaction from a non‑attacker makes successful exploitation more difficult in practice.
OpenCVE Enrichment