Impact
A flaw in the Security component of Oracle Hyperion Financial Management 11.2.25.0.000 allows an attacker who already has high‑privileged credentials on the network and can reach the Hyperion service over HTTP to read all data exposed by the service. The vulnerability is triggered by an improper authorization check, effectively making it an information disclosure weakness (CWE‑200) that can also facilitate privilege escalation (CWE‑269). It is considered easily exploitable, meaning an attacker can leverage it without special tools or advanced skills. Successful exploitation results in a breach of confidentiality for critical financial information, potentially granting an attacker full access to the system’s data set.
Affected Systems
Oracle Corporation’s Hyperion Financial Management, version 11.2.25.0.000, is the only product variant identified as affected. No other vendors, products, or version ranges are mentioned in the advisory.
Risk and Exploitability
The base CVSS v3.1 score is 4.9, indicating a medium severity focus on confidentiality impact. EPSS is under 1 %, suggesting a very low likelihood of exploitation, and the vulnerability is not catalogued in CISA’s KEV list. The likely attack vector is a network‑bound HTTP connection, but the flaw requires that the attacker already holds high‑privileged rights on the target network. While the potential impact includes full data exposure for privileged users, the overall threat is constrained to systems where high‑privileged accounts are granted or misused.
OpenCVE Enrichment