Impact
Easily exploitable vulnerability in Oracle Hyperion Financial Management allows an attacker who already possesses high‑privileged credentials and can reach the system over HTTP to compromise the entire application. The flaw results in loss of confidentiality, integrity, and availability, effectively giving an attacker full control of the platform.
Affected Systems
Oracle Corporation’s Hyperion Financial Management product, version 11.2.25.0.000, is the only affected version. The vulnerability is confined to the Security component of that release.
Risk and Exploitability
The CVSS v3.1 base score of 7.2 indicates high impact and moderate exploitability. The EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a network‑based HTTP connection; therefore, the attacker needs to be within the network scope and hold high‑privilege access to successfully exploit the flaw.
OpenCVE Enrichment