Impact
The Oracle Hyperion Financial Management product contains a flaw in its Security component that permits an unauthenticated attacker with network access over HTTP to bypass authentication and gain unauthorized read or write access to all data available within the application. The vulnerability, classified as CVSS v3.1 8.2, indicates high impact on confidentiality, moderate impact on integrity, and no impact on availability. No user interaction, privilege escalation, or code execution is required; the attacker can directly compromise data confidentiality and integrity through the web interface.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000 is the only version affected. The flaw is specific to this release and does not apply to earlier or later releases unless they contain the same unpatched component.
Risk and Exploitability
The vulnerability has an EPSS score of less than 1%, indicating a very low probability of exploitation at present. It is not listed in the CISA KEV catalog, meaning no publicly known exploits have been confirmed. The attack vector is network‑based via HTTP, with low attack complexity and no authentication required, allowing any Internet‑reachable host to potentially compromise the system. While the flaw does not provide arbitrary code execution, the ability to read or modify all financial data presents a significant threat to confidentiality and integrity of sensitive business information.
OpenCVE Enrichment