Impact
The vulnerability resides in the Security component of Oracle Hyperion Financial Management. An attacker with network access via HTTP can obtain unauthorized access to critical data or even all data stored in the product, and can cause a partial denial of service. The CVSS v3.1 vector indicates network access, low attack complexity, low privilege requirement, no user interaction, and a user‑local scope with high confidentiality impact and low availability impact.
Affected Systems
Oracle Corporation’s Hyperion Financial Management, version 11.2.26.0.000, is affected. No other versions or variants were identified as vulnerable in the available data.
Risk and Exploitability
The CVSS Base Score is 7.1, reflecting a moderate to high severity. The EPSS score is below 1%, indicating a very low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the flaw can be triggered via standard HTTP traffic from a low‑privileged attacker, the risk remains significant for organizations that expose the product to internal or untrusted networks.
OpenCVE Enrichment