Impact
The vulnerability is located in the Security component of Oracle Hyperion Financial Management. It allows an attacker with low privileges to compromise the system over HTTP, leading to a complete takeover. This results in full loss of confidentiality, integrity, and availability for the application. The weakness is identified as CWE-269, an access control failure that permits unauthorized privilege escalation.
Affected Systems
Oracle Corporation’s Hyperion Financial Management, version 11.2.26.0.000, is affected.
Risk and Exploitability
The attack can be launched over a network with no user interaction. The CVSS score of 8.8 reflects a high impact. The EPSS score indicates that exploitation is currently low (<1%), and the vulnerability is not listed in CISA’s KEV catalog. However, because a successful exploit leads to total control of the application, organizations must treat it as a high‑risk issue and address it promptly.
OpenCVE Enrichment