Impact
An unauthenticated attacker with network access via HTTP can exploit a flaw in Oracle Hyperion Financial Management 11.2.26.0.000. The vulnerability allows the attacker to create, delete, or modify critical data and to trigger a partial denial of service. It is a weakness that bypasses authentication and improperly enforces access control, resulting in high integrity impact and moderate availability impact as reflected in the CVSS score of 8.2.
Affected Systems
The affected product is Oracle Hyperion Financial Management version 11.2.26.0.000, provided by Oracle Corporation.
Risk and Exploitability
The CVSS base score is 8.2, and the EPSS score is below non-zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires no authentication and can be performed over the network through the HTTP interface, potentially compromising the integrity of critical financial data and causing service disruption.
OpenCVE Enrichment