Impact
The vulnerability resides in the Security component of Oracle Hyperion Financial Management, allowing an unauthenticated attacker to send HTTP requests that create, delete, or modify critical data. The flaw does not require authentication, so any user who can reach the HTTP interface can impact the confidentiality and integrity of the entire data set exposed by Hyperion.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000 is the only affected release reported. No other versions are listed as vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 7.4 highlights serious confidentiality and integrity consequences, while an EPSS score below 1% indicates a low real‑world exploitation probability. The flaw is not catalogued in CISA’s KEV list. Still, the attack vector is over HTTP, so any network access to the Hyperion server opens a path for exploitation; this risk is amplified in environments lacking proper network segmentation.
OpenCVE Enrichment