Impact
A vulnerability in the Security component of Oracle Hyperion Financial Management allows a low‑privileged attacker with network access via HTTP to gain unauthorized access to critical data or even full access to all accessible data, and to cause a partial denial of service. The weakness is an improper authorization flaw, CWE‑284, enabling the attacker to bypass normal access controls. The impact includes data confidentiality loss and availability degradation, as described by the CVSS vector with high confidentiality impact and low availability impact.
Affected Systems
Oracle Corporation’s Hyperion Financial Management, version 11.2.25.0.000, exposed through HTTP on the network. The exploit requires no elevated privileges on the host but only requires the attacker to be able to reach the application over the network.
Risk and Exploitability
The CVSS 3.1 base score is 7.1, indicating a high‑severity vulnerability. The EPSS score is <1%, indicating a very low exploitation probability, and the vulnerability is not yet listed in the CISA KEV catalog. Based on the CVSS vector, the attack vector is network, with an attacker able to exploit the flaw over HTTP without any user interaction. The low‑privileged requirement means that any user who can reach the application can potentially gain unauthorized data access or disrupt services.
OpenCVE Enrichment