Impact
Oracle Hyperion Financial Management contains a security flaw that can be triggered by a low‑privilege attacker with HTTP access. The flaw can be leveraged to cause a partial denial of service, limiting the availability of financial reporting functions. The CVSS base score of 3.1 reflects the limited impact, but the weakness remains exploitable.
Affected Systems
Oracle Corporation’s Hyperion Financial Management version 11.2.25.0.000.
Risk and Exploitability
While the CVSS score is low, the EPSS score of <1% indicates a very low probability of exploitation but not zero. The vulnerability is not listed in CISA KEV, suggesting no known active exploitation. The likely attack vector involves an attacker on the network targeting the Hyperion application over HTTP with low privileges. The risk is focused on availability, potentially disrupting financial reporting for users who rely on the product.
OpenCVE Enrichment