Impact
The vulnerability in Oracle Hyperion Financial Management version 11.2.26.0.000 occurs in its security component and allows any network user to connect over HTTP without authentication. A successful exploit enables the attacker to create, delete or modify critical financial data, or obtain complete read access to all stored information, thereby destroying the confidentiality and integrity of the application’s data. The weakness is an authorization bypass and missing authentication, identified by CWE‑287 and CWE‑306.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000 is the sole affected product. The flaw resides in the security component of this release, so any deployment of that version is vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 reflects high impact severity; yet the EPSS score of less than 1% indicates that exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalogue, meaning no public exploits are tracked. Attackers would target the exposed HTTP interface, requiring no credentials, and can reach the target over the network. While exploitation probability remains low, the potential impact is high, warranting immediate mitigation.
OpenCVE Enrichment