Impact
The vulnerability resides in the server component of Oracle Hyperion Financial Reporting, allowing a low‑privileged attacker who can reach the system over HTTP to read critical data that is intended to be protected. This flaw can result in unauthorized access to important financial information or full access to all data the application makes available, without affecting integrity or availability.
Affected Systems
Oracle Corporation’s Hyperion Financial Reporting version 11.2.25.0.000 is the only supported release flagged as vulnerable by Oracle’s advisory.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 signals a moderate severity issue focused solely on confidentiality. Because the exploit requires only network access via HTTP and minimal authentication, it is inferred that the potential impact is significant for any organization exposing this application. The EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV, indicating limited observed exploitation but still a substantial risk if the system remains exposed.
OpenCVE Enrichment