Impact
A flaw in Oracle Hyperion Financial Management version 11.2.26.0.000 permits an unauthenticated attacker to exploit the Security component through an HTTP interface and forcibly terminate or hang the application. The resulting denial‑of‑service can repeatedly crash the system, disrupting financial reporting and data processing. This weakness is rooted in uncontrolled resource consumption.
Affected Systems
The Oracle Hyperion Financial Management product, version 11.2.26.0.000, built by Oracle Corporation.
Risk and Exploitability
The CVSS score of 7.5 reflects a high availability impact, while the EPSS score of less than 1 % indicates very low current exploitation probability. The vulnerability is not listed in CISA's KEV catalog. Because the exploit requires only network access via HTTP and no credential, an attacker could launch an attack from any location with connectivity to the Hyperion service. The impact would be immediate denial of service; no depends on how critical the Hyperion service is to operations and whether it is exposed to untrusted networks.
OpenCVE Enrichment