Impact
An HTTP-based vulnerability in Oracle Hyperion Financial Management 11.2.25.0.000 allows a low‑privileged attacker to gain unauthorized access to sensitive financial data. The flaw exists in the security component and can be exploited from the network without user interaction. Successful exploitation compromises confidentiality by rendering all data accessible to the attacker, but does not directly affect integrity or availability.
Affected Systems
The affected product is Oracle Hyperion Financial Management version 11.2.25.0.000, released by Oracle Corporation.
Risk and Exploitability
The vulnerability has a CVSS v3.1 base score of 6.5, with network attack vector, low access complexity, low privilege required, no user interaction, and a single impact type of confidentiality. The EPSS score is not available, and the vulnerability is not listed in CISA's KeV catalog. The likely attack path uses standard HTTP access to trigger the flaw, requiring only a basic network connection and minimal attacker credentials.
OpenCVE Enrichment