Impact
The vulnerability resides in the Server component of Oracle Hyperion Financial Reporting, allowing a low‑privileged attacker who has network access over HTTP to perform unauthorized updates, inserts or deletes, and to read data that should be protected. The impact is a moderate loss of confidentiality and integrity, as indicated by the CVSS Base Score of 4.2.
Affected Systems
Oracle Corporation's Hyperion Financial Reporting version 11.2.25.0.000 is the only affected release. No other editions or versions are listed as impacted.
Risk and Exploitability
The overall severity is moderate, with a CVSS score of 4.2 and an EPSS score of < 1%, indicating a low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit this weakness by sending crafted HTTP requests to the server component, and the CVSS vector indicates that only network access and low privilege are required, with the user interface not being a factor.
OpenCVE Enrichment