Impact
The vulnerability resides in the Security component of Oracle Hyperion Financial Management. It permits a low‑privileged attacker with network access over HTTP to perform unauthorized updates, inserts, deletes or reads on a subset of the application’s data, and to induce a partial denial of service. The flaw results from insufficient access control checks, identified as CWE‑284, and has a CVSS v3.1 base score of 6.3 reflecting moderate severity with impacts on confidentiality, integrity and availability.
Affected Systems
Affected systems are Oracle Hyperion Financial Management releases version 11.2.25.0.000, which is explicitly listed as vulnerable in Oracle’s August 2026 CSPU security bulletin.
Risk and Exploitability
The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L) indicates a network attack requiring only low privilege. The EPSS score is < 1 %, indicating a very low but nonzero probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker does not need elevated or local administrative credentials—low‑privileged accounts are sufficient to exploit the flaw. Attackers would need to craft and send a malicious HTTP request to a vulnerable Hyperion instance.
OpenCVE Enrichment