Impact
A flaw in the Security component of Oracle Hyperion Financial Management 11.2.25.0.000 allows an unauthenticated attacker that can reach the system over HTTPS to create, delete or modify data. Successful exploitation leads to unauthorized access to or alteration of critical financial data, as the vulnerability provides complete data modification privileges for anyone who can reach the HTTPS interface.
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000 for clients using the Hyperion Financial Management product.
Risk and Exploitability
The CVSS v3.1 score of 7.4 indicates high severity, underscoring significant confidentiality and integrity impacts. While the EPSS score is not available, the vulnerability is not listed in CISA’s KEV catalog. The attack vector is remotely via HTTPS, requiring only network connectivity and no authentication. Given the lack of an exploit probability score, the risk remains high because the flaw permits total data modification privileges once an attacker gains network access.
OpenCVE Enrichment