Impact
A flaw in the Security component of Oracle Hyperion Financial Management allows a low‑privileged attacker with network access to the HTTP interface to compromise the application, ultimately enabling full takeover of the platform. The weakness is an improper privilege management issue (CWE‑269), permitting the bypass of authentication controls and granting broad access rights. The vulnerability is rated highly with a CVSS 3.1 base score of 8.8, indicating severe impacts on confidentiality, integrity and availability.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000 is the only product affected. The issue resides in the Security component of this edition, as defined by the vendor.
Risk and Exploitability
The high CVSS score reflects the severe potential for compromise, but the EPSS score of less than 1 % indicates that real‑world exploitation remains rare at present. The flaw is not listed in CISA’s KEV catalog. Attackers need only network access to the HTTP interface and a low‑privileged credential; they can send crafted requests that bypass authentication checks and gain full control over the application.
OpenCVE Enrichment