Impact
A flaw in Oracle Hyperion Financial Reporting allows a low‑privileged attacker with network access via HTTP to fully compromise the application, resulting in the attacker gaining complete control and affecting confidentiality, integrity, and availability of financial data.
Affected Systems
The vulnerability affects Oracle Hyperion Financial Reporting version 11.2.25.0.000.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and although EPSS is low at less than 1%, the vulnerability can still be exploited over a public HTTP interface by any low‑privileged attacker with network access. The issue is not listed in CISA KEV, but remote attackers only require connectivity and minimal permissions to achieve full compromise of the application, affecting confidentiality, integrity, and availability.
OpenCVE Enrichment