Impact
The flaw is in the server component of Oracle Hyperion Financial Reporting and allows an unauthenticated attacker to interact over HTTP. The sidestepping of authentication and requirement for a human interaction outside the attacker’s immediate control enable the attacker to traverse the system. When exploited, the attacker can read critical data, gain full visibility of all data accessible through the application, and carry out unauthorized updates, inserts, or deletions, thereby compromising confidentiality and integrity.
Affected Systems
Oracle Corporation’s Hyperion Financial Reporting, version 11.2.25.0.000. This is the only product version explicitly listed as affected.
Risk and Exploitability
The CVSS 3.1 base score of 5.9 denotes moderate severity with high attack complexity, no privilege escalation, and a user interaction requirement. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating it has not yet been exploited at scale. Nevertheless, once active, the attack offers an attacker substantial data‑gathering and data‑manipulation capabilities. The attack vector is network‑based via HTTP and can only be performed with the cooperation of a separate user.
OpenCVE Enrichment