Impact
The Oracle Hyperion Financial Management product contains an easily exploitable flaw in its Security component. This flaw is an instance of CWE‑269 and CWE‑284. A high privileged attacker who can reach the application over HTTP may gain unauthorized access to critical data or achieve full data set access, and can also force the application to hang or crash, creating a denial‑of‑service condition. The flaw carries confidentiality and availability impacts, reflected in a CVSS 3.1 Base Score of 6.5.
Affected Systems
Only Oracle Hyperion Financial Management version 11.2.25.0.000 is affected; no other versions were mentioned in the advisory.
Risk and Exploitability
The vector allows network access with HTTP, and the required privilege level is high. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog, but the potential for compromising all exposed data or causing a denial‑of‑service remains significant. The CVSS score of 6.5 indicates a moderate severity that warrants timely remediation.
OpenCVE Enrichment