Impact
The vulnerability originates in the Security component of Oracle Hyperion Financial Management. An unauthenticated attacker with network access via HTTP can trigger unauthorized update, insert, or delete operations on data, as well as read access to a subset of eligible data. This flaw is a CWE‑284 Improper Access Control weakness and is rated with a CVSS 3.1 base score of 4.8, indicating moderate confidentiality and integrity impact.
Affected Systems
Affected systems include Oracle Hyperion Financial Management version 11.2.25.0.000. No higher or lower versions are mentioned in the data.
Risk and Exploitability
The risk is moderate; the EPSS score is < 1% and indicates a very low yet non‑zero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The description indicates that an unauthenticated attacker with network access via HTTP can compromise Oracle Hyperion Financial Management, so the likely attack vector is over the network through HTTP and does not require privileged access. While exploitation is considered difficult, successful exploitation could allow an attacker to alter or delete sensitive financial records or read confidential entries.
OpenCVE Enrichment