Impact
The vulnerability in Oracle Hyperion Financial Management allows a low‑privileged attacker with network access via HTTP to read critical data. The likely weaknesses are information exposure (CWE-200) and improper privilege management (CWE-269), which permit unauthorized data exposure without requiring elevated privileges and enable attackers to access resources beyond the intended scope. Successful exploitation can result in the compromise of sensitive financial information or full read access to all data exposed by the application.
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000, as released by Oracle Corporation, is the only product version identified as vulnerable. No other variants or patch levels are mentioned in the advisory.
Risk and Exploitability
The CVSS v3.1 base score of 5.3 indicates a medium risk largely due to confidentiality impact. The vulnerability involves information exposure (CWE-200) and improper privilege management (CWE-269) and is exploitable over the network via the HTTP interface and requires only low‑privileged access on the target system. Because the EPSS score is less than 1%, the likelihood of exploitation is low, though the presence of a remote HTTP entry point suggests potential for broader threat. The issue is not listed in the CISA KEV catalog, implying that no confirmed public exploits exist yet, although custom attacks may be possible.
OpenCVE Enrichment