Impact
The vulnerability resides in the security component of Oracle Hyperion Financial Management and allows a low‑privileged attacker with network access on HTTP to cause the application to hang or crash repeatedly. The flaw is considered difficult to exploit; successful exploitation results in a denial of service that completely interrupts availability of the Hyperion instance without affecting confidentiality or integrity.
Affected Systems
Affected systems are Oracle Hyperion Financial Management 11.2.25.0.000. No other versions are mentioned as impacted.
Risk and Exploitability
The CVSS 3.1 score is 5.3 and only the availability metric is impacted. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalogue. Attackers would need network connectivity to the Hyperion HTTP interface and do not require elevated privileges. Because the exploit requires specific conditions and is not currently widely observed, the risk is moderate but the impact on business continuity can be significant if the service is critical.
OpenCVE Enrichment