Impact
The flaw in Oracle Hyperion Financial Management permits an attacker to perform unauthorized creation, deletion, or modification of data, as well as gain unauthorized access to critical information. The vulnerability can be triggered remotely by an unauthenticated attacker with network access via HTTP, allowing the alteration or removal of financial records and compromising the confidentiality of the stored data.
Affected Systems
Oracle Hyperion Financial Management, version 11.2.26.0.000, is the only publicly documented impacted release. Users running this version without the official security update are exposed to the described flaw.
Risk and Exploitability
The CVSS score of 7.4 indicates a high‑severity risk with significant confidentiality and integrity impacts. The EPSS score is below 1%, implying that real‑world exploitation is currently unlikely, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is an unauthenticated remote adversary accessing the Hyperion application over HTTP. Successful exploitation would require network access to the Hyperion instance and would allow the attacker to create, delete, or alter critical data without authentication or authorization checks.
OpenCVE Enrichment