Impact
The flaw resides in the security component of Oracle Hyperion Financial Management and allows a low-privileged attacker who can reach the system over HTTP to obtain read-only access to critical or all application data. The vulnerability is described as difficult to exploit and provides no direct operating-system compromise; however, it results in a high confidentiality impact while leaving integrity and availability unaffected, as reflected in the CVSS vector.
Affected Systems
Oracle Corporation’s Oracle Hyperion Financial Management version 11.2.25.0.000 is affected. No patch or workaround has been released at the time of this advisory, so protection must focus on behavioral controls until an update is available.
Risk and Exploitability
The CVSS base score of 5.3 classifies the issue as moderate severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, implying no known used exploits. The attack can be carried out from any Internet accessible interface using HTTP and requires the attacker to operate under a low-privilege account, as inferred from the CVSS vector.
OpenCVE Enrichment