Impact
The vulnerability resides in the Security component of Oracle Hyperion Financial Management and can be triggered via unauthenticated HTTP requests. An attacker able to reach the application can create, delete, or modify critical data, effectively bypassing standard access controls. The flaw results in simultaneous confidentiality and integrity loss for all data exposed by the application, as reflected by its CVSS 7.4 score.
Affected Systems
Affected systems include Oracle Hyperion Financial Management version 11.2.26.0.000. No other versions or variants are listed in the CNA data. The vulnerability exists in the product’s Security module and is limited to the specified release.
Risk and Exploitability
With a CVSS base score of 7.4, the risk is moderate to high. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not tracked in CISA’s KEV catalog. The attack vector is remote over the network via HTTP, requiring no user authentication or additional privileges. If an attacker succeeds, they gain unrestricted read/write access to the application’s data, potentially compromising all financial records managed by the system.
OpenCVE Enrichment