Impact
Oracle Hyperion Financial Reporting 11.2.25.0.000 is vulnerable to an unauthorized‑access issue that allows an attacker without authentication to access the web service over HTTP, resulting in unauthorized read access to a subset of the application's data. The vulnerability does not affect integrity or availability, but it does allow a low impact confidentiality breach as reflected in the CVSS score of 3.7.
Affected Systems
Affected systems are servers running Oracle Hyperion Financial Reporting version 11.2.25.0.000. The exact product is Oracle Hyperion Financial Reporting, a component of the Oracle Hyperion suite deployed in enterprise environments.
Risk and Exploitability
The CVSS base score of 3.7 indicates low severity. Exploitation requires network connectivity to the web endpoint and can be performed by an unauthenticated user. The EPSS score is 0.208% (0.00208), and the vulnerability is not listed in the CISA KEV catalog, suggesting limited current exploitation activity. Nonetheless, the potential for data disclosure warrants prompt mitigation.
OpenCVE Enrichment