Impact
Vulnerability in the Secure component of Oracle Hyperion Financial Management 11.2.26.0.000 allows an attacker to create, delete, or modify critical data and gain full access to all data, resulting in loss of confidentiality and integrity. The flaw is an authentication bypass, classified as CWE-287 and CWE-306. Its CVSS score of 9.1 reflects the high impact on data security.
Affected Systems
Only Oracle Hyperion Financial Management version 11.2.26.0.000 from Oracle Corporation is affected. Any instance of this product that has not applied the vendor's patch remains vulnerable. No other versions or products are listed as impacted.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity vulnerability. The EPSS score of 0.00404 indicates a very low probability of exploitation. The vulnerability is not yet listed in the CISA KEV catalogue. Based on the description, the attack vector is likely remote via TCP and does not require authentication, allowing unauthenticated attackers to compromise the system and manipulate data.
OpenCVE Enrichment