Impact
It is an information disclosure vulnerability that allows an attacker with low‑privileged network access over HTTP to read any data that Oracle Hyperion Financial Management can serve. Successful exploitation results in unauthorized disclosure of critical financial data or full access to all data accessible through the application. The flaw is rooted in the security component of the application and affects confidentiality only, with no reported impact on integrity or availability.
Affected Systems
The affected release is Oracle Hyperion Financial Management 11.2.25.0.000. The weakness resides in the application’s security layer and may impact other products that interact with Hyperion because the CVE notes a scope change.
Risk and Exploitability
The CVSS v3.1 base score of 7.7 indicates a high severity for confidentiality. The EPSS score of <1% reflects a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Successful exploitation requires only low‑privileged HTTP access, enabling an attacker to retrieve all data the application exposes. Because of the scope change, related products might also be impacted if they communicate with the vulnerable Hyperion instance. The vulnerability is associated with CWE-200 (Information Exposure) and CWE-269 (Privilege Management).
OpenCVE Enrichment