Impact
The Oracle Hyperion Financial Management version 11.2.26.0.000 contains an easily exploitable vulnerability located in its Security component. Attackers with low privileges who have network access over HTTP can compromise the application, leading to total takeover of the system. The CVSS score of 8.8 reflects severe impacts to confidentiality, integrity, and availability, with no requirement for user interaction or advanced attacker resources.
Affected Systems
Affected product: Oracle Hyperion Financial Management from Oracle Corporation, version 11.2.26.0.000. No additional affected versions are disclosed. The vulnerability is not listed in the CISA KEV catalog.
Risk and Exploitability
The attack vector is Network, with low attacker complexity and low privilege. Exploitation can be performed over HTTP without user interaction, and the scope of impact is limited to the affected system. The CVSS score indicates high severity, yet the EPSS score of less than 1% suggests a low current probability of exploitation. The lack of public exploits and the severe takeover potential warrant urgent remediation.
OpenCVE Enrichment