Impact
This vulnerability resides in the security component of Oracle Hyperion Financial Management. An unauthenticated attacker who can reach the system over a network TCP connection may bypass authentication and gain the ability to create, delete or modify critical financial data, resulting in a high confidentiality and integrity impact.
Affected Systems
Affected is Oracle Corporation’s Oracle Hyperion Financial Management 11.2.26.0.000. This is the sole version explicitly noted as vulnerable by the vendor.
Risk and Exploitability
The CVSS base score of 9.1 indicates a severe threat. The EPSS score of 0.00308 (less than 1%) indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the vulnerability can be exploited remotely via TCP by an unauthenticated user, and successful exploitation would give the attacker unauthorized control over all data accessible through the application. Because the attack requires only network access, any externally reachable instance is a potential target.
OpenCVE Enrichment