Impact
Oracle Hyperion Financial Management is vulnerable to an authentication bypass that permits an unauthenticated attacker with TCP network access to gain unauthorized read or modify permissions to critical application data. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data, as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data.
Affected Systems
The product impacted is Oracle Hyperion Financial Management version 11.2.26.0.000. No other product variants are listed as affected. Oracle has identified this specific build as the only one containing the vulnerability.
Risk and Exploitability
The CVSS 3.1 score of 8.2 indicates high severity with significant confidentiality impact and modest integrity damage. The EPSS score of less than 1% suggests that exploitation attempts are unlikely at present, and the vulnerability is not yet listed in CISA’s KEV catalog. Nevertheless, the vulnerability is easily exploitable over the network by an unauthenticated actor, and it can be leveraged to read or modify data without detection. Organizations using the affected version should consider the risk high enough to warrant prompt remediation.
OpenCVE Enrichment