Impact
The vulnerability is a security flaw in Oracle Hyperion Financial Management that allows an unauthenticated attacker to connect over HTTP and gain direct access to the application. Successful exploitation can lead to the disclosure of critical financial data or every piece of data exposed through the system. The weakness originates from inadequate handling of sensitive information, leading to disclosure of critical data when accessed without authentication.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000 is affected.
Risk and Exploitability
The CVSS v3.1 score of 7.5 indicates high impact on confidentiality. The EPSS score of less than 1% suggests that active exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. However, the attack vector is straightforward: an external actor with network access can send a request over HTTP without authentication, implying that the flaw is easily exploitable in environments where the service is reachable from untrusted networks.
OpenCVE Enrichment