Impact
The vulnerability in Oracle Hyperion Financial Management allows an unauthenticated attacker with network access via HTTP to compromise the system, enabling unauthorized access to critical financial data and the possibility of a partial denial of service. The flaw resides in the product’s Security component and is triggered without any authentication or privileged credentials. Exploit would expose sensitive data to an attacker and could disrupt service availability, although the disruption is described as partial.
Affected Systems
Only Oracle Hyperion Financial Management version 11.2.25.0.000 is affected. The software is distributed by Oracle Corporation and the failure occurs in its Security component, which is reachable over HTTP.
Risk and Exploitability
The vulnerability has a CVSS 3.1 base score of 8.2, indicating high severity for confidentiality and some availability impact. The EPSS score of 0.00403 indicates an extremely low probability of exploitation at this time, though lack of authentication requirements means the risk remains theoretically exploitable. The vulnerability is not listed in CISA’s KEV catalog, yet remote attackers could leverage it over HTTP to gain unauthorized data access and possibly disrupt services.
OpenCVE Enrichment