Impact
The vulnerability in Oracle Hyperion Financial Management is a CWE-284 Access Control weakness that allows an unauthenticated attacker with network access via HTTP to modify accessible data and cause a partial denial of service. An attacker can perform unauthorized insert, update, or delete operations on the system’s data. The impact scores both integrity and availability, with a CVSS base score of 6.5 and a vector element indicating that no privileges or user interaction are required.
Affected Systems
Affected systems include Oracle Corp.’s Hyperion Financial Management version 11.2.25.0.000. The vulnerability affects the Security component and requires network access through HTTP.
Risk and Exploitability
CVSS score of 6.5 indicates moderate severity. EPSS <1% suggests low exploitation probability. The vulnerability is not listed in CISA KEV. Attack requires no authentication and only network access, implying HTTP-based exploitation of the web interface. Despite the low EPSS, the potential for unauthorized data modification and partial denial remains significant, warranting prompt remediation.
OpenCVE Enrichment