Impact
Oracle Hyperion Financial Management contains a flaw in its security component that allows unauthenticated attackers with network access over HTTP to obtain unauthorized access to critical data or full database contents and to trigger a partial denial of service. The CVSS 3.1 score of 8.2 highlights a high impact on confidentiality and availability, with no impact on integrity as indicated by the vector.
Affected Systems
The vulnerability affects Oracle Hyperion Financial Management version 11.2.25.0.000. No other versions are mentioned as impacted in the available data.
Risk and Exploitability
The attack vector is inferred to be a network-based HTTP request that can be sent without authentication. The EPSS score of <1% indicates a very low but nonzero probability of exploitation, and the vulnerability is not listed in CISA KEV. The high CVSS score signals a serious risk if the application is exposed to the internet, while the lack of an official exploitation reference suggests attackers could still craft exploits using the known flaw but external proof of exploitation has not yet been reported.
OpenCVE Enrichment