Impact
The vulnerability is located in the security component of Oracle Hyperion Financial Management. It allows a high‑privileged attacker with network access via HTTP to fully compromise the application, granting the attacker control over the system and enabling alteration, disclosure, or destruction of financial data. The flaw represents an authorization control weakness and strikes confidentiality, integrity, and availability.
Affected Systems
The affected product is Oracle Hyperion Financial Management, version 11.2.25.0.000, issued by Oracle Corporation. No other releases are indicated as vulnerable in the advisory, so the risk applies only to this specific build.
Risk and Exploitability
The CVSS v3.1 base score of 7.2 indicates high severity and describes a network attack (AV:N) with low attack complexity and high privileges required (PR:H). The EPSS score of < 1 % suggests a very low probability of exploitation in the wild at this time, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector is HTTP requests to the application’s security endpoints performed by an attacker who already has privileged access. Because the flaw requires privileged credentials, the exploitation is limited to accounts that have been compromised or already granted high‑level permissions, but once accessed the attacker can achieve full system takeover and disrupt or manipulate financial operations.
OpenCVE Enrichment