Impact
The vulnerability resides in the security component of Oracle Hyperion Financial Management. A low‑privileged attacker who can reach the system over HTTP can exploit this flaw to compromise the application, resulting in a full takeover with complete confidentiality, integrity, and availability loss.
Affected Systems
Affected Vendor: Oracle Corporation. Product: Oracle Hyperion Financial Management, version 11.2.25.0.000. No other versions are listed as affected.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates high risk. With an attack vector of network and minimal privileges, the exploit could be performed remotely by an attacker who can send HTTP requests to the application. The EPSS score is < 1%, and the vulnerability is not in CISA KEV, but the high impact warrants prompt attention. A likely attack path involves sending crafted requests to the vulnerable component over HTTP, bypassing normal authorization controls.
OpenCVE Enrichment