Impact
A flaw in the Security component of Oracle Hyperion Financial Management enables an unauthenticated attacker with network access through HTTP to trigger a controlled hang or crash, resulting in a full denial of service. The vulnerability relies on an uncontrolled resource consumption condition, identified as CWE-400, and can be exercised with minimal effort once connectivity to the affected service is available.
Affected Systems
Oracle Hyperion Financial Management 11.2.26.0.000 is affected. Only this product version is listed as vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 indicates a significant impact on availability. The EPSS score of less than 1% shows a very low, but non‑zero, probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires only unauthenticated HTTP access, making the attack vector simple and widely available over a network.
OpenCVE Enrichment