Impact
A flaw in the Security component of Oracle Hyperion Financial Management allows a low‑privileged attacker with basic network access over HTTP to read protected data or gain full visibility into all data the application can access, due to insufficient privilege checks (CWE-269) and information exposure (CWE-200). The vulnerability is tied to confidentiality, leaving integrity and availability unaffected.
Affected Systems
The affected product is Oracle Hyperion Financial Management, version 11.2.25.0.000. Users running this instance are vulnerable and could expose sensitive financial information to attackers who can reach the system over HTTP.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates a moderate to high risk level. The EPSS score is listed as < 1 %, implying a very low but non‑zero probability of exploitation, and the vulnerability is not present in CISA’s KEV catalog. Attackers only need low privileges and remote HTTP access, meaning a compromised internal user or machine could potentially exploit the flaw without sophisticated privileges.
OpenCVE Enrichment