Impact
The vulnerability resides in the Security component of Oracle Hyperion Financial Management and permits a low‑privilege attacker with network access over HTTP to compromise the system. Once exploited, an adversary can obtain unauthorized access to critical data or even full access to all hyperion data that the application serves. The weakness results in a confidentiality impact, as an attacker can read sensitive financial information without proper authorization.
Affected Systems
Oracle Corporation’s Oracle Hyperion Financial Management, version 11.2.25.0.000. No other versions are listed as affected in the CNA data.
Risk and Exploitability
The CVSS v3.1 score of 6.5 indicates moderate severity, and the vector shows a network‑based attack requiring low privileges. The probability of exploitation is unknown because an EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker can leverage standard HTTP requests to trigger the flaw, making it easily exploitable from within the network.
OpenCVE Enrichment