Impact
The vulnerability resides in the Security component of Oracle Hyperion Financial Management (11.2.26.0.000). A low‑privileged attacker with network access via HTTP can exploit the flaw to compromise the system. Successful exploitation results in a full takeover with loss of confidentiality, integrity, and availability. The weakness is classified as CWE‑269, which relates to improper privilege management.
Affected Systems
Affected product is Oracle Hyperion Financial Management version 11.2.26.0.000. No other versions or products are listed as impacted.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates moderate–high severity, reflecting the ability to impact all data and services. The EPSS score of less than 1% suggests low estimated exploitation probability at this time. The vulnerability is not included in the CISA KEV catalog. Attack likely originates from a network‑accessible HTTP endpoint, requiring only low privileges to initiate the exploit. While the flaw is difficult to exploit, once successful it can result in a complete takeover.
OpenCVE Enrichment