Impact
Oracle Hyperion Financial Reporting’s Server component contains a flaw that permits attackers who can reach the system over HTTP to execute unauthorized select, insert, update, or delete operations against the database. Because authentication is not required, the vulnerability allows an adversary to alter report data integrity and read confidential parts of the data set. The CVSS vector indicates no user interaction and low attack complexity, translating into confidentiality and integrity impacts while leaving availability unaffected.
Affected Systems
This issue affects Oracle Corporation’s Hyperion Financial Reporting product, specifically the Server component of version 11.2.25.0.000. No other versions or products are listed as vulnerable.
Risk and Exploitability
The CVSS base score of 6.5 classifies the vulnerability as moderate severity, and the EPSS score is < 1%, so the exact likelihood of exploitation is uncertain. Because the flaw is exploitable over the public network without credentials, the potential for compromise is high. The server may be attacked from anywhere that can reach its HTTP interface, leading to unauthorized data modification or disclosure. The vulnerability is not yet listed in CISA’s KEV catalog.
OpenCVE Enrichment