Impact
The vulnerability is an easily exploitable flaw in the security component of Oracle Hyperion Financial Management that allows a low‑privileged attacker with network access over HTTP to compromise the application. Successful exploitation can lead to a full takeover of the Hyperion system, affecting confidentiality, integrity and availability as indicated by the CVSS 3.1 score.
Affected Systems
The affected version is 11.2.26.0.000 of Oracle Hyperion Financial Management, a product of Oracle Corporation. Any installations of that specific version are vulnerable, with no other versions or variants listed.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high severity. The EPSS score indicates a very low probability of exploitation, less than 1%, and the vulnerability is not listed in CISA KEV. The attack vector is remote over HTTP, requiring low privileges but no user interaction, which makes the risk significant for exposed systems.
OpenCVE Enrichment