Impact
This vulnerability in Oracle Hyperion Financial Management version 11.2.25.0.000's Security component allows an attacker without authentication to read a subset of data over HTTP. The primary impact is a confidentiality loss with no direct effect on integrity or availability. The weakness corresponds to improper authorization and information disclosure.
Affected Systems
Oracle Corporation’s Oracle Hyperion Financial Management, specifically the 11.2.25.0.000 release. No other vendors or product versions are mentioned as affected.
Risk and Exploitability
The CVSS base score of 3.7 reflects a low overall risk driven mainly by the confidentiality impact. EPSS data shows an exploitation probability of less than 1%, indicating a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path involves an unauthenticated attacker with network access who sends crafted HTTP requests that bypass authentication checks and retrieve restricted data. No special conditions beyond normal HTTP connectivity are required for exploitation.
OpenCVE Enrichment