Impact
The vulnerability is an unchecked resource‑usage flaw in the Security component of Oracle Hyperion Financial Management that lets an unauthenticated attacker with network access over TCP cause the application to hang or crash repeatedly. As a result, the service becomes unavailable, compromising the availability of financial reporting processes without affecting data confidentiality or integrity.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000 is affected. No other versions are listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 signifies a high availability impact. The EPSS score of less than 1 % suggests the probability of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. Attackers can reach the target over the network using TCP without any authentication, making the flaw potentially exploitable in open or poorly secured environments. Consequently, the issue should be treated as a high‑priority availability risk and fixed as soon as possible.
OpenCVE Enrichment