Impact
The vulnerability is an HTTP-based access control flaw in Oracle Hyperion Financial Management 11.2.25.0.000. A low-privileged attacker with network access can exploit the flaw to read any financial data stored in the system. The weakness resides in the security component, enabling unauthorized access without user interaction. The CVSS vector confirms that only confidentiality is affected, with no impact on integrity or availability.
Affected Systems
Oracle Corporation’s Hyperion Financial Management version 11.2.25.0.000 is the only product impacted, as listed by the CNA.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 marks this as a moderate‑severity weakness. Attackers can reach the flaw over the default HTTP interface, need no special credentials beyond normal network access, and exploit it with low access complexity. The EPSS score is less than 1%, indicating exploitation is expected to be rare, and the flaw is not present in the CISA KEV catalog. The likely attack path requires merely an HTTP request to a privileged endpoint, with no additional prerequisites.
OpenCVE Enrichment