Impact
An information exposure flaw exists in the Security component of Oracle Hyperion Financial Management that allows a low‑privileged attacker with network access over HTTP to compromise the application. Successful exploitation can lead to unauthorized disclosure of critical data and partial denial of service. This vulnerability enables an attacker with low privilege to obtain high confidentiality impact while affecting availability moderately.
Affected Systems
The affected product is Oracle Hyperion Financial Management version 11.2.26.0.000, maintained by Oracle Corporation. No other vendors or versions have been reported as affected by the current advisory.
Risk and Exploitability
The CVSS v3.1 base score of 7.1 indicates a high risk, with a threat vector of network, low authentication, and low is available, and the vulnerability is not listed in CISA KEV, with an EPSS score of < 1%, indicating a very low but nonzero exploitation probability. An attacker could exploit the HTTP interface remotely without any user interaction, leading to data compromise or service disruption. The that this vulnerability could compromise sensitive financial information.
OpenCVE Enrichment