Impact
Oracle Hyperion Financial Management version 11.2.25.0.000 suffers from an Improper Access Control flaw in its Security component. An unauthenticated attacker who can reach the application over TLS may exploit this weakness to create, delete, or modify critical data and gain unrestricted access to all data stored by the product. The flaw allows the attacker to bypass both authentication and authorization checks, leading to severe confidentiality and integrity losses.
Affected Systems
Oracle Corporation’s Oracle Hyperion Financial Management product version 11.2.25.0.000 is affected. No other products or versions are listed as impacted.
Risk and Exploitability
With no authentication required, the vulnerability is readily exploitable over a network connection using TLS, and the CVSS score of 10.0 indicates critical severity. The EPSS score of < 1% indicates a low but non‑zero probability of exploitation; combined with the critical CVSS score and lack of mitigation measures the overall risk remains high. The vulnerability is not currently listed in the CISA KEV catalog, but its impact warrants immediate attention.
OpenCVE Enrichment