Impact
A flaw in the security component of Oracle Hyperion Financial Management 11.2.25.0.000 allows an unauthenticated attacker with network access over HTTP to read a subset of data that should be protected. The weakness enables disclosure of sensitive financial information, compromising confidentiality but not integrity or availability. This flaw involves improper access control (CWE-284).
Affected Systems
Oracle Hyperion Financial Management version 11.2.25.0.000 is affected; this applies to installations that expose the web interface to network traffic.
Risk and Exploitability
The vulnerability has a CVSS v3.1 base score of 5.3 and is considered easily exploitable. It requires only network access to the HTTP port and no authentication. The EPSS score indicates a low but non-zero exploitation probability (< 1%), and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread or targeted exploitation has not been reported as of this analysis.
OpenCVE Enrichment