Impact
This vulnerability resides in the security component of Oracle Hyperion Financial Management, affecting version 11.2.25.0.000. A low‑privileged attacker with network access over HTTP can exploit this flaw, potentially gaining full control of the application and compromising confidentiality, integrity and availability of the financial data.
Affected Systems
The affected product is Oracle Hyperion Financial Management 11.2.25.0.000 from Oracle Corporation.
Risk and Exploitability
The CVSS base score of 7.5 indicates moderate‑to‑high severity, with a network attack vector, high authentication difficulty, low privilege and no user interaction. The EPSS score of < 1% indicates a very low but non‑zero exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires only network access to the Hyperion HTTP interface and does not require privileged credentials, making this a realistic risk for exposed deployments.
OpenCVE Enrichment