Impact
A flaw in the Security component of Oracle Hyperion Financial Management allows an unauthenticated attacker who can reach the application over HTTP to create, delete, or modify critical data. The same weakness can also trigger frequent hangs or complete crashes, impacting system availability. The flaw is essentially an improper access control issue that permits both integrity and availability violations.
Affected Systems
Oracle Corporation’s Hyperion Financial Management, version 11.2.26.0.000.
Risk and Exploitability
The CVSS v3.1 base score of 9.1 signifies a substantial risk to data integrity and availability. The EPSS score of less than 1% indicates that, while the vulnerability is known, exploitation in the wild is currently rare. The vulnerability has not been flagged in the CISA KEV catalog. Attackers can exploit the flaw by sending crafted HTTP requests from any network location, relying on the lack of authentication or authorization before destructive operations are possible.
OpenCVE Enrichment