Impact
The vulnerability resides in the Security component of Oracle Hyperion Financial Management and allows an attacker with low privileges and network access through HTTP to bypass authentication checks to read sensitive financial data. The flaw is classified as a medium severity issue with a CVSS base score of 6.5, affecting confidentiality only.
Affected Systems
Oracle Hyperion Financial Management, version 11.2.25.0.000, is the only affected release. The vulnerability is documented for this particular version; other releases are not known to be impacted.
Risk and Exploitability
The flaw can be exploited remotely from any system that can reach the Hyperion HTTP endpoint, requiring a low-privileged attacker with network access via HTTP. The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% shows a very low but nonzero exploitation probability. The vulnerability is not listed in CISA's KEV catalog, implying no publicly documented exploits yet, but the path remains feasible for opportunistic attackers.
OpenCVE Enrichment