Impact
The Oracle Hyperion Financial Management product (version 11.2.25.0.000) contains a security flaw that allows an unauthenticated attacker with network access over HTTP to compromise the application. Successful exploitation requires human interaction from a user other than the attacker and results in the ability to update, insert, or delete data as well as read restricted data. This flaw is caused by improper authorization (CWE‑269) and cross‑site request forgery (CWE‑352) mechanisms within the security component, allowing the attacker to bypass normal access controls. The flaw produces confidentiality and integrity impacts reflected in the CVSS 3.1 score of 5.4.
Affected Systems
Oracle Corporation’s Hyperion Financial Management, specifically the 11.2.25.0.000 release, is affected by this vulnerability.
Risk and Exploitability
Because the EPSS score indicates an exploitation probability of less than 1 % and the vulnerability is not listed in the CISA KEV catalog, the likelihood of widespread recent exploitation is uncertain, yet the impact remains significant for organizations that rely on Hyperion for financial data integrity. The recommended response is therefore to mitigate through patching or hardening network access to the affected component.
OpenCVE Enrichment