Impact
The vulnerability lies in the Security component of Oracle Hyperion Financial Management. A low-privileged user with network connectivity over TCP can bypass authentication controls, gaining full administrative access. Attacks can fully alter financial data, disrupt services, and compromise the confidentiality, integrity, and availability of the system.
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000, distributed by Oracle Corporation. The affected component is the Security module of the product, commonly used in enterprise financial reporting environments.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 and impact vector (C:H; I:H; A:H) indicate a high-remediation priority. An EPSS score of less than 1% suggests that exploitation is currently rare or unobserved, yet the remote TCP attack vector with low privilege means any host able to reach the service is vulnerable. The vulnerability is not listed in CISA’s KEV catalogue, so no publicly observed exploits are documented, but the high severity and low privileged requirement underscore the urgency of timely remediation.
OpenCVE Enrichment