Impact
The vulnerability resides in the Server component of Oracle Hyperion Financial Reporting and permits an unauthenticated attacker with network access via HTTP to alter or add data and to read data that the application already exposes. It requires human interaction from a user other than the attacker. Once that condition is met, the exploit can modify or read restricted data, impacting the confidentiality and integrity of reports and financial information.
Affected Systems
The only explicitly affected product is Oracle Hyperion Financial Reporting version 11.2.25.0.000; no other sub‑products or versions are identified as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 6.1 reflects moderate severity with low authentication and local user interface requirements. Human interaction is required, which lowers the overall exploitation likelihood. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog, indicating limited publicly observed exploitation. Nonetheless, the potential for unauthorized data changes and scope expansion warrants attention.
OpenCVE Enrichment