Impact
A security flaw exists in the Oracle Hyperion Financial Management component "Security" for version 11.2.25.0.000. An unauthenticated user who can reach the application over HTTP can exploit this flaw to read a subset of data that should be protected, resulting in a confidentiality impact that allows attackers to obtain sensitive financial information.
Affected Systems
The vulnerability affects only Oracle Corporation's Oracle Hyperion Financial Management product version 11.2.25.0.000. No other versions or vendor products are listed as affected.
Risk and Exploitability
With a CVSS 3.1 base score of 5.3, the risk level is moderate. The EPSS score is < 1%, indicating a very low probability of exploitation. Because the flaw is described as easily exploitable over a network connection, an attacker with network access can obtain data immediately via standard HTTP requests. The vulnerability is not listed in CISA's KEV catalog, so no known active exploits are documented.
OpenCVE Enrichment