Impact
The vulnerability resides in the security component of Oracle Hyperion Financial Management version 11.2.26.0.000. A low‑privileged attacker with network access over HTTP can exploit the flaw to obtain unauthorized access to critical data or all data stored in the application, and the attacker can also trigger a partial denial of service. The weakness leads to a high confidentiality impact and a low availability impact, reflected by the CVSS 3.1 base score of 7.1.
Affected Systems
Oracle Corporation’s Oracle Hyperion Financial Management version 11.2.26.0.000 is affected. No other versions or products are currently listed as impacted.
Risk and Exploitability
The CVSS base score of 7.1 indicates substantial severity. The EPSS score of <1% suggests that the vulnerability has a very low current exploitation probability, and it is not listed in CISA’s Known Exploited Vulnerabilities catalog. However, because the flaw is described as easily exploitable by a low‑privileged attacker who can reach the application over HTTP, the risk to organizations that expose the Hyperion application to broader networks remains significant. If the application is publicly reachable or accessed from untrusted networks, the likelihood of compromise is moderate.
OpenCVE Enrichment