Impact
A missing authentication check in the Security component enables any user who can reach the web interface over HTTP to query protected data. The vulnerability does not require credentials, enabling an attacker to read sensitive business information that should be inaccessible. The flaw leads to a breach of confidentiality where critical data can be exposed, since any data the application is configured to serve may be retrieved by the unauthenticated user.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000 is the only product affected as indicated by the CNA information. No other vendors or product lines are impacted.
Risk and Exploitability
The CVSS base score of 7.5 classifies this issue as high severity due to its confidentiality impact. The EPSS score is reported as less than 1 %, suggesting that automated exploitation is uncommon but not impossible. The attack requires only network connectivity to the HTTP interface and no credentials; consequently, an attacker could use simple scripts to discover and read data. The vulnerability is not listed in the CISA KEV catalogue, indicating no confirmed widespread exploitation, yet the potential for data leakage remains significant.
OpenCVE Enrichment