Impact
Oracle Hyperion Financial Management is susceptible to a remotely exploitable flaw in its security component that allows a low‑privileged attacker with network visibility through HTTP to take full control of the application. The vulnerability can result in complete compromise of the system’s confidentiality, integrity, and availability.
Affected Systems
The affected product is Oracle Hyperion Financial Management version 11.2.25.0.000, released by Oracle Corporation. No other versions are listed as vulnerable in the current advisory.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates a high‑impact flaw. With an EPSS score of less than 1 % and the vulnerability not being listed in the CISA KEV catalog, proof‑of‑concept exploitation is currently low but possible. Based on the CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), a remote attacker can send specially crafted HTTP requests without user interaction to trigger the flaw, leading to a takeover of the Hyperion service and associated data.
OpenCVE Enrichment