Impact
The vulnerability allows an attacker with low privileges and network access via HTTP to fully compromise Oracle Hyperion Financial Management. An exploitation would provide the attacker with the same capabilities as the affected account, enabling complete takeover of the application and full compromise of confidentiality, integrity and availability. The weakness stems from an improper access control flaw in the Security component (argument against authorization checks).
Affected Systems
Oracle Corporation’s Hyperion Financial Management product, version 11.2.26.0.000, is affected. No other versions or components are listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 Base Score of 8.8 indicates high severity with complete impact to all CIA pillars. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV, so the probability of exploitation is low. Attackers with a low‑privileged account on any exposed instance could, in theory, exploit this flaw, but the very low EPSS suggests exploitation is unlikely. Consequently, the risk is high, but the likelihood of exploitation remains low if the affected system is exposed to an untrusted network.
OpenCVE Enrichment