Impact
A flaw in the security component of Oracle Hyperion Financial Management allows an attacker to send HTTP requests without any authentication, granting access to sensitive financial data. The vulnerability can lead to unauthorized read of critical information or, in worst cases, complete exposure of all data stored in the application, while leaving system integrity and availability untouched. The weaknesses are classified as CWE-269 and CWE-284, reflecting improper access control and improper authorization controls respectively. The CVSS 3.1 base score of 7.5 highlights a moderate to high severity, driven by a network attack vector, low complexity, and no required user interaction.
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000 is vulnerable. The product operates behind standard HTTP interfaces and is susceptible to unauthenticated requests that can bypass authorization checks.
Risk and Exploitability
With a CVSS score of 7.5, this vulnerability poses a relatively high risk to confidentiality through an easily exploitable remote HTTP interface. The EPSS score indicates an exploitation probability of less than 1%, and the flaw is not listed in the CISA KEV catalog, but its high score and straightforward network path mean that attackers can trigger it from anywhere on the network without prior access or credentials. The attack requires only standard HTTP traffic, making containment a priority for affected deployments.
OpenCVE Enrichment