Impact
The vulnerability is located in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. It permits an attacker who can reach the system over HTTP to bypass authentication controls and access the application as an authorized user. This results in confidential financial data being exposed, while integrity and availability remain unaffected.
Affected Systems
Oracle Hyperion Financial Management 11.2.25.0.000 from Oracle Corporation is the sole product and version identified as vulnerable in the advisory.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 classifies the flaw as high severity. The EPSS score of less than 1 % indicates that active exploitation is currently unlikely. Because exploitation requires only HTTP access over the network, the vulnerability can be triggered by any unauthenticated user with network reachability to the Hyperion instance. The flaw is not listed in the CISA KEV catalog, so there is no public evidence of widespread attacks, but the confidentiality risk warrants proactive mitigation.
OpenCVE Enrichment