Impact
The vulnerability resides in the Security component of Oracle Hyperion Financial Management and permits an unauthenticated attacker with HTTP network access to compromise the application. Successful exploitation grants the attacker unauthorized view of critical financial data and the ability to insert, update, or delete system, effectively enabling data breach and tampering. The weakness is inferred to be improper authentication and is present in version 11.2.26.0.000, deployed by Oracle Corporation under the Hyperion Financial Management suite. No other versions or variations are documented as vulnerable in the supplied information.
Affected Systems
Affected systems include Oracle Hyperion Financial Management version 11.2.26.0.000, distributed by Oracle Corporation. No other versions or editions are documented as vulnerable in the supplied data.
Risk and Exploitability
With a CVSS base score of 8.2, this flaw rates as high severity, impacting confidentiality and integrity of financial data. The EPSS score indicates a low but non‑zero likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers require only network access to HTTP endpoints and no authentication. If the service is exposed to untrusted networks, the risk escalates rapidly but remains mitigated by internal network segmentation and access controls.
OpenCVE Enrichment