Impact
This vulnerability exists in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. A low-privileged attacker who can reach the application via HTTP can exploit the flaw, leading to a complete takeover of the system. The flaw allows the attacker to compromise confidentiality, integrity, and availability, as reflected in the CVSS 3.1 score of 8.8.
Affected Systems
Oracle Hyperion Financial Management, version 11.2.26.0.000. No other versions were reported as affected.
Risk and Exploitability
The CVSS base score of 8.8 indicates high severity, while the EPSS score of less than 1 % reflects a currently low likelihood of exploitation. The vulnerability requires network access over HTTP and only a low-privileged account, meaning the attack surface is moderate. Because it is not listed in CISA’s KEV catalog, there is no public evidence of active exploitation, but the potential impact is total system compromise. The vector appears to be remote, authenticated through a low-privileged account, achieved via HTTP connections to the Hyperion service.
OpenCVE Enrichment