Impact
Oracle Hyperion Financial Reporting version 11.2.25.0.000 exposes a vulnerability that can be triggered by an unauthenticated attacker who can reach the HTTP interface. The flaw permits the attacker to obtain unauthorized access to critical data and, in some cases, to modify or delete that data. The impact is primarily on confidentiality and integrity, with no direct denial of service effect. The weakness is a combination of insufficient access control (CWE-284) and improper authorization (CWE-863).
Affected Systems
The affected product is Oracle Hyperion Financial Reporting, version 11.2.25.0.000. It runs on the server component and is accessible over standard HTTP ports. No other versions or products are listed as impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability with a high attack complexity and no privilege or user interface required. The EPSS score of < 1% indicates a very low probability of exploitation at this time. Though it is not listed in the CISA KEV catalog, the remote, unauthenticated nature of the attack vector means that any network‑connected system could be compromised if unpatched. The vulnerability can be exploited without prior authentication, making it a high‑priority risk for exposed or remotely accessible instances.
OpenCVE Enrichment