Impact
An unauthenticated attacker who can reach Oracle Hyperion Financial Management over HTTP can create, delete, or modify data and can force the application to hang or crash repeatedly, effectively denying service. This access control weakness (CWE‑284) allows bypassing authentication, resulting in integrity and availability impacts, but does not directly expose sensitive information via leaks.
Affected Systems
Oracle Corporation’s Hyperion Financial Management product, specifically version 11.2.25.0.000.
Risk and Exploitability
The CVSS base score of 9.1 highlights severe risk; the attack vector is network‑based and requires only an HTTP connection, making it broadly exploitable. EPSS score of < 1% indicates a very low exploit probability, and the vulnerability is not listed in CISA’s KEV catalog, but the lack of a known exploit does not reduce the urgency implied by the high CVSS score.
OpenCVE Enrichment