Impact
An exploitable flaw in the security component of Oracle Hyperion Financial Management lets a low‑privileged user with HTTP network access gain unauthorized access to critical data or all data stored in the system, and can vulnerability can be leveraged to read sensitive financial information and disrupt availability, threatening both confidentiality and availability of the application.
Affected Systems
Oracle Corporation’s Hyperion Financial Management product, version 11.2.26.0.000, is affected by this vulnerability.
Risk and Exploitability
The CVSS v3.1 base score of 7.1 highlights the impact on confidentiality and score and absence from CISA’s KEV catalog suggest limited evidence of exploitation in the wild. Attackers would require only low privileges and access to the HTTP interface to exploit the flaw, making the vector straightforward for network‑based attackers. The EPSS score of < 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment