Impact
The vulnerability in Oracle Hyperion Financial Management allows a low‑privileged attacker with network access via HTTP to obtain unauthorized access to critical data. It is a flaw in the product’s security controls that enables non‑privileged users to read sensitive financial information, potentially exposing all data accessible by the application.
Affected Systems
Oracle Corporation’s Oracle Hyperion Financial Management version 11.2.25.0.000 is affected.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates moderate severity focused on confidentiality. The EPSS score of 0.00371 indicates a very low but nonzero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers need only network access to an exposed HTTP endpoint and no elevated privileges to exploit the flaw, potentially gaining read access to all data processed by the application.
OpenCVE Enrichment