Impact
A flaw in the Security component of Oracle Hyperion Financial Management allows an attacker with low-level user rights who can reach the system over HTTP to compromise the application. The vulnerability can be leveraged to read sensitive financial records or to gain unrestricted read access to all data exposed by the system, and it also permits the attacker to trigger a partial denial of service. The weakness is a classic improper access control issue that exposes confidential data and hampers availability.
Affected Systems
Oracle Corporation’s Oracle Hyperion Financial Management version 11.2.25.0.000 is affected. This includes deployments that expose the HTTP interface and run the security component as described.
Risk and Exploitability
The vulnerability has a CVSS v3.1 base score of 7.1, indicating moderate to high impact to confidentiality and availability. The EPSS score is < 1%, indicating a very low but non-zero exploitation probability, and the issue is not listed in CISA’s KEV catalog. Based on the description, the attack vector is network-based via HTTP and requires only low privileges; however, the low EPSS score indicates that exploitation likelihood is minimal for most installations.
OpenCVE Enrichment