Impact
Oracle Hyperion Financial Management version 11.2.26.0.000 contains a flaw in its security component that allows an unauthenticated attacker to bypass authentication via HTTP. The weakness falls under CWE‑306 (Missing Authentication). Successful exploitation grants the attacker unauthorized access to critical application data, compromising confidentiality without affecting integrity or availability.
Affected Systems
Oracle Hyperion Financial Management, version 11.2.26.0.000, used by organizations managing financial data. The vulnerability is confined to this specific version of the product.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 reflects a medium‑to‑high severity focused on confidentiality impact. The EPSS score is below 1 %, indicating a low current exploitation probability, and the issue is not listed in CISA’s KEV catalog. Attackers can launch the exploit over plain HTTP with no credentials, making the attack path straightforward and potentially granting full data access.
OpenCVE Enrichment