Impact
The vulnerability resides in the Security component of Oracle Hyperion Financial Management and permits a low‑privilege attacker with network access over HTTP to compromise the system. Once exploited, an adversary can obtain unauthorized access to critical data or even full access to all hyperion data that the application serves. The weakness results in a confidentiality impact, as an attacker can read sensitive financial information without proper authorization.
Affected Systems
Oracle Corporation’s Oracle Hyperion Financial Management, version 11.2.25.0.000. No other versions are listed as affected in the CNA data.
Risk and Exploitability
The CVSS v3.1 score of 6.5 indicates moderate severity, and the vector shows a network‑based attack requiring low privileges. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can leverage standard HTTP requests to trigger the flaw, indicating that the vulnerability is easily exploitable from within the network.
OpenCVE Enrichment