Impact
The vulnerability resides in the Oracle Hyperion Financial Reporting server component and permits a low‑privileged attacker with network access over HTTP to perform unauthorized update, insert, or delete operations on data that is accessible to the application. This condition leads to an integrity impact, allowing the attacker to alter the trustworthiness of reported financial information. The weakness is characterized as an access control flaw (CWE‑284).
Affected Systems
Oracle Hyperion Financial Reporting version 11.2.25.0.000, deployed under Oracle Corporation.
Risk and Exploitability
The CVSS 3.1 base score is 2.6, indicating a low severity risk, and the EPSS score is less than 1 %. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote over HTTP and requires an attacker with low privileges; successful exploitation also demands human interaction from a user other than the attacker, implying the need to persuade or rely on an internal user to trigger a data modification action.
OpenCVE Enrichment