Impact
A flaw in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000 enables an unauthenticated attacker with network access via HTTP to compromise the application. Successful exploitation can lead to a full takeover of the system, exposing, modifying, or deleting sensitive financial data and affecting confidentiality, integrity, and availability as indicated by the CVSS vector.
Affected Systems
Oracles Hyperion Financial Management 11.2.25.0.000 is affected; no other products or versions are specifically mentioned as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 marks this as a high‑severity vulnerability. The EPSS score of less than 1% indicates a low likelihood of widespread exploitation at present, but the vulnerability is easily exploitable from any exposed HTTP endpoint and requires no authentication. The lack of a CISA KEV listing does not reduce the potential impact, so administrators should treat it as a high‑priority risk.
OpenCVE Enrichment