Impact
A flaw in the Security component of Oracle Hyperion Financial Management 11.2.25.0.000 allows an unauthenticated attacker that can reach the system over HTTPS to create, delete or modify data. Successful exploitation leads to unauthorized access to or alteration of critical financial data, as the vulnerability provides complete data modification privileges for anyone who can reach the HTTPS interface.
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000 for clients using the Hyperion Financial Management product.
Risk and Exploitability
The CVSS v3.1 base score of 7.4 highlights significant confidentiality and integrity impacts. The EPSS score of < 1% indicates a very low predicted exploitation probability, yet the vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote over HTTPS and requires no authentication. Since the vulnerability provides full data modification privileges, the potential impact remains severe if exploited.
OpenCVE Enrichment