Impact
Oracle Hyperion Financial Management 11.2.26.0.000 contains a flaw in its security component that permits an attacker to perform a remote attack via HTTP with no authentication. The vulnerability allows the attacker to create, delete, or modify critical system data, or gain access to all data available within Oracle Hyperion Financial Management, thereby impacting confidentiality and integrity.
Affected Systems
The affected system is Oracle Hyperion Financial Management version 11.2.26.0.000.
Risk and Exploitability
The CVSS 3.1 base score is 9.1, indicating high severity. The EPSS score is less than 1%, which suggests that exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an unauthenticated network request over HTTP targeting the application’s exposed endpoints. Successful exploitation would allow an attacker to modify or delete financial data without raising an immediate alarm.
OpenCVE Enrichment