Impact
A vulnerability exists in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The flaw allows a low‑privileged attacker who can reach the application over HTTP to gain unauthorized access to critical financial data. Successful exploitation can enable reading of sensitive information and modification of data, including insert, update or delete operations, thereby compromising confidentiality and, to a lesser extent, integrity.
Affected Systems
Oracle Hyperion Financial Management, version 11.2.26.0.000
Risk and Exploitability
The CVSS 3.1 Base Score of 7.1 indicates a moderate-to‑high severity. The EPSS score of less than 1 % suggests a low likelihood of exploitation at present, and the vulnerability is not catalogued in CISA’s KEV list. Based on the description, the attack vector likely involves sending crafted HTTP requests that bypass or degrade authentication controls, allowing a low‑privileged actor to read or alter data without additional privileges.
OpenCVE Enrichment