Impact
Oracle Hyperion Financial Management’s security component is vulnerable to unauthenticated attackers who can access the application over HTTP. The flaw enables attackers to insert, update or delete data that requires proper authorization (CWE‑284) and to trigger a partial denial of service, compromising data integrity and reducing application availability. The CVSS v3.1 base score of 4.2 reflects these non‑catastrophic but still significant integrity and availability impacts.
Affected Systems
Only Oracle Hyperion Financial Management version 11.2.25.0.000 is affected; the risk applies to all users who can reach the application on that version.
Risk and Exploitability
The EPSS score of less than 1 % indicates that current evidence of exploitation is extremely low, and the vulnerability is not listed in the CISA KEV catalog. Attackers require network access to the public HTTP interface but no privileges. Importantly, the description states that successful attacks necessitate human interaction by a third party, which makes the exploitation path difficult. Thus, despite the vulnerability’s existence, the likelihood of it being actively exploited in the wild is considered low, though the potential impact should not be underestimated.
OpenCVE Enrichment