Impact
An unauthenticated network attacker can exploit a flaw in the security component of Oracle Hyperion Financial Management to create, delete, or modify critical data. The vulnerability provides complete access to all application data, compromising confidentiality and integrity. This flaw corresponds to CWE-287 (Authentication Bypass) and CWE-306 (Missing Authentication).
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000 from Oracle Corporation is affected.
Risk and Exploitability
The CVSS score of 9.1 signals a high severity risk, while the EPSS score of less than 1% indicates the current probability of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is a direct TCP connection to an exposed Hyperion instance, requiring no authentication; successful exploitation would allow an attacker to gain full read/write access to all data stored by the application.
OpenCVE Enrichment