Impact
The vulnerability in Oracle Hyperion Financial Management allows a low‑privileged attacker who can reach the application over HTTP to gain unauthorized access to critical or all data stored by the system. The flaw lies in the security component, permitting the attacker to circumvent normal access controls and expose confidential information. This is reflected in the CVSS 3.1 base score of 6.5, which is driven solely by a confidentiality impact.
Affected Systems
Affected vendors and products include Oracle Corporation’s Oracle Hyperion Financial Management, specifically version 11.2.25.0.000 of the product. No other versions or components are listed as impacted in the advisory.
Risk and Exploitability
The CVSS severity rating of 6.5 indicates that the vulnerability is of medium severity, with confidentiality as the primary concern. The EPSS score is not available and the vulnerability is not listed in CISA KEV. The likely attack path involves a low‑privilege user accessing the web interface over HTTP; the vulnerability is considered easily exploitable under these conditions. Deploying the official patch mitigates the issue, while the absence of KEV listing means there is no current evidence of widespread exploitation.
OpenCVE Enrichment