Impact
The vulnerability is in Oracle Hyperion Financial Management 11.2.25.0.000, specifically in the security component, and allows a low‑privileged attacker with network access to HTTP to create, modify, or delete data, or gain unauthorized access to all accessible data. The impact includes loss of confidentiality and integrity of critical financial data. The weakness is a lack of proper access control, leading to these unauthorized operations.
Affected Systems
Affected vendor: Oracle Corporation. Product: Oracle Hyperion Financial Management. Version: 11.2.25.0.000. The vulnerability is reported for the security component and affects systems accessible over HTTP.
Risk and Exploitability
The CVSS v3.1 base score is 8.1. The EPSS score is < 1%, and the vulnerability is not listed in KEV. The vector indicates that the attack can be performed over the network with low authentication privileges and no user interaction, implying fairly high exploitability for compromised systems. Attackers with network access to the HTTP endpoint can exploit the weakness to alter or steal data, potentially impacting business operations.
OpenCVE Enrichment