Impact
The vulnerability lies in the Security component of Oracle Hyperion Financial Management, enabling a high‑privilege attacker with network access over HTTP to fully compromise the application. A successful exploitation can result in complete takeover of Oracle Hyperion Financial Management, granting the attacker full access to confidential data, the ability to modify or delete information, and potential disruption of availability.
Affected Systems
This issue affects Oracle Corporation’s Hyperion Financial Management product, specifically version 11.2.25.0.000. No other versions are listed as vulnerable.
Risk and Exploitability
The CVSS base score of 7.2 indicates high severity, and the description indicates that the flaw is easily exploitable. The attack vector is network‑based, requiring HTTP access to the affected system and high privileges to succeed. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The potential for a full system takeover remains significant.
OpenCVE Enrichment