Impact
The vulnerability resides in the Security component of Oracle Hyperion Financial Management and allows an unauthenticated attacker to compromise the system via HTTP. Successful exploitation can lead to unauthorized access to critical data or complete data exposed by the application, resulting in a significant confidentiality impact.
Affected Systems
The affected product is Oracle Hyperion Financial Management version 11.2.26.0.000.
Risk and Exploitability
The CVSS 3.1 score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based HTTP request from an unauthenticated attacker, implying remote exploitation without prior authentication. Because no patch is currently listed, the risk persists for systems exposed to the internet, necessitating immediate mitigation and monitoring.
OpenCVE Enrichment