Impact
A flaw in the security component of Oracle Hyperion Financial Management gives a high‑privileged attacker who can reach the application over HTTP the ability to read critical data or all data accessible through the system. The vulnerability abuses insufficient access controls and can expose confidential financial information, representing a direct breach of data confidentiality. The weakness is classified as an authorization flaw.
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000 is affected. No other versions were indicated as vulnerable.
Risk and Exploitability
The attack vector is network‑based through HTTP; the attacker must already possess high privileges within the network to exploit the flaw. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog, further reducing the current threat level. However, the CVSS score of 4.4 highlights a moderate confidentiality impact, meaning that a successful attack would compromise sensitive data even though it does not affect integrity or availability.
OpenCVE Enrichment