Impact
The vulnerability is an improper access control flaw located in the Security component of Oracle Hyperion Financial Management. A low‑privileged attacker who can reach the system over HTTP can bypass authorization checks and read any data available to the application, including critical or all application data. The weaknesses are CWE-269 and CWE-284. The damage is limited to confidentiality, with no impact on integrity or availability reported.
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000. No other versions or product variants are listed as affected.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates a moderate to high risk. The attack can be carried out with only network access and low privileges, and no user interaction is required. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, but the description notes it is easily exploitable and could have significant confidentiality impact if discovered by a low‑privileged adversary.
OpenCVE Enrichment