Impact
The issue is located in the Security component of Oracle Hyperion Financial Management. An attacker who has only low-privileged credentials and can reach the system over standard HTTP is able to fully control the target, compromising confidentiality, integrity, and availability. Because the vulnerability includes a scope change, it may also affect other Oracle products that share components or configurations.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000 is affected. The vulnerability may also extend to additional Oracle products through a scope change, potentially broadening its impact.
Risk and Exploitability
The CVSS 3.1 base score of 9.9 classifies the flaw as critical, indicating that a successful attack would grant complete control of the affected Hyperion instance. The EPSS score is reported as less than 1%, suggesting a low estimated probability of exploitation in the wild, yet the flaw remains technically highly exploitable with only standard HTTP access and low-privileged credentials. Although the vulnerability is not currently listed in the CISA KEV catalog, the combination of severe impact and easily satisfied network prerequisites highlights the importance of timely remediation.
OpenCVE Enrichment