Impact
An insecure authorization check (CWE-284) in the Security component of Oracle Hyperion Financial Management 11.2.25.0.000 allows a high‑privileged attacker with network access via HTTP to read restricted financial data and to trigger a partial denial of service. The attack requires the attacker to have network reachability to the HTTP interface and high privileges within the system. The vulnerability results in modest confidentiality loss and modest availability degradation.
Affected Systems
The affected product is Oracle Hyperion Financial Management, version 11.2.25.0.000, from Oracle Corporation. No other versions or vendors are listed as impacted.
Risk and Exploitability
With a CVSS base score of 3.3, this weakness is considered low severity. The EPSS score is 0.00215, and the CVE is not listed in the CISA KEV catalog. The exploit requires a high‑privileged attacker who can reach the application over HTTP, making the vulnerability difficult to exploit in practice. Nonetheless, an attacker who succeeds can obtain sensitive financial data and cause a limited disruption to service.
OpenCVE Enrichment