Impact
A weakness in the Security component of Oracle Hyperion Financial Management 11.2.25.0.000 permits a low-privileged attacker with network access over HTTP to trigger application hangs and crashes, and to read, update, or delete data that should be protected. The flaw can lead to denial of service and unauthorized data tampering or disclosure, affecting confidentiality, integrity, and availability.
Affected Systems
Oracle Corporation’s Hyperion Financial Management product, version 11.2.25.0.000, is impacted; no other Oracle products or versions are mentioned as affected.
Risk and Exploitability
The CVSS v3.1 base score of 6.4 indicates a moderate severity. An EPSS score of <1% shows a low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack can be carried out over the network through the HTTP interface, requiring only low privileges and high attack complexity, resulting in a moderate risk of moderate impact.
OpenCVE Enrichment