Impact
Oracle Hyperion Financial Management users can exploit an easily exploitable flaw in the Security component that allows a low‑privileged attacker with network access over HTTP to fully compromise the application. Successful exploitation results in a complete takeover, compromising confidentiality, integrity, and availability of the system. The CVSS 3.1 Base Score of 8.8 reflects the severe impact on all three fundamental security categories.
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000 is affected. The vulnerability is present in the Security component of this software and applies to all installations that have not applied a patch or upgrade for this release.
Risk and Exploitability
The high CVSS score indicates a significant risk for organizations using the affected product. The vulnerability is exploitable over the network via HTTP without user interaction, and only low privileges are required to launch the attack. The EPSS score is < 1%, indicating a very low probability of exploitation, and the absence in the CISA KEV catalog does not diminish the potential for active exploitation. The attack vector is likely remote web traffic, and an attacker could achieve full system compromise once the flaw is used.
OpenCVE Enrichment