Impact
Oracle Hyperion Financial Management contains a security element flaw allowing an unauthenticated attacker that can reach the application over HTTP to compromise the system. A successful attack provides the attacker unauthorized access to critical data or full access to all data the application exposes. The vulnerability is a confidentiality breach; integrity and availability are not directly affected.
Affected Systems
The affected product is Oracle Hyperion Financial Management, version 11.2.26.0.000, as specified by the official CNA. No other sub‑components are listed.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high severity vulnerability that can be exploited with low effort. The EPSS score of less than 1% signals a low probability of active exploitation in the wild, but the ease of exploitation and the lack of authentication requirement make it a high‑risk target for attackers who discover the service. The vulnerability is not listed in the CISA KEV catalog, so publicly known exploits have not yet been recorded, but the potential impact remains significant. Attackers can reach the flaw over the network via standard HTTP ports, using the publicly exposed interface without any credentials.
OpenCVE Enrichment