Impact
The Oracle Hyperion Financial Management security component contains a flaw that allows an attacker who only has low privileges to connect over HTTP and access data that should be restricted to higher‑privileged roles. As a result, the attacker can read any data the application exposes, including critical financial information that would normally be restricted to higher‑privileged users. The vulnerability does not affect integrity or availability; its single purpose is to compromise confidentiality, a high‑level impact as described by the CWE identifiers for information exposure, improper privilege management, and improper access control.
Affected Systems
This issue affects Oracle Hyperion Financial Management version 11.2.25.0.000 across all platforms where the product is deployed. The vulnerability may also influence other Oracle applications that share configuration or run within the same environment, as the description notes a possible scope change that could extend the impact beyond the primary product.
Risk and Exploitability
The CVSS 3.1 base score of 7.7 corresponds to a moderate‑to‑high risk, while the EPSS score of less than 1% indicates that, as of now, the likelihood of exploitation in the wild is very low. The vulnerability is not listed in CISA’s KEV catalog, implying no publicly known exploits. The most plausible attack path involves a low‑privilege or unauthenticated user accessing the exposed HTTP interface from an external network to read sensitive data.
OpenCVE Enrichment