Impact
This vulnerability allows a low‑privileged attacker with network access to the Oracle Hyperion Financial Management web interface to read all exposed data and cause a partial denial of service. The impact includes confidentiality loss for critical data and availability degradation.
Affected Systems
Oracle Corporation’s Oracle Hyperion Financial Management version 11.2.25.0.000 is affected. No other versions or products are listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 indicates a high impact, with significant confidentiality and availability effects. The EPSS score is less than 1%. The vulnerability is not yet catalogued in CISA’s KEV list. Based on the description, it is inferred that the attacker requires low‑privileged network access to the Hyperion instance over HTTP, but the advisory does not explicitly state whether authentication is required or if any elevated privileges are necessary.
OpenCVE Enrichment