Impact
This vulnerability exists in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000, allowing an unauthenticated attacker with network access via HTTP to compromise the application. A successful exploit can lead to full takeover of the system, giving the attacker the ability to read, modify, or delete any financial data and potentially execute arbitrary code on the host. The weakness is a form of improper input validation that permits remote code execution.
Affected Systems
The affected product is Oracle Hyperion Financial Management 11.2.25.0.000. No other versions or products were specifically identified as impacted. The vulnerability lies within the Security component of this version, so any deployment of 11.2.25.0.000 that is not patched remains at risk.
Risk and Exploitability
The CVSS 3.1 Base Score of 9.8 marks this vulnerability as critical. While the EPSS score is not available, the lack of a KEV listing does not reduce the high potential impact. Because the attacker needs only network access over HTTP and no authentication or user interaction, exploitation is highly feasible for exposed deployments. Administrators should treat this as an urgent threat and prioritize remediation.
OpenCVE Enrichment