Impact
Oracle Hyperion Financial Management version 11.2.26.0.000 contains a security component flaw that is easily exploitable. A low-privileged attacker who can reach the application over HTTP can compromise the system, resulting in full takeover. The vulnerability would compromise confidentiality, integrity, and availability of the application data and services.
Affected Systems
Vendors affected are Oracle Corporation, product Oracle Hyperion Financial Management, specifically version 11.2.26.0.000. No other versions or components are listed as impacted.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 indicates a high severity impact across all CIA properties. The EPSS score is less than 1%, indicating a low probability of exploitation at the time of assessment, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network-based via HTTP, with low privilege required. If exploited, the attacker can achieve a full takeover of the Hyperion instance.
OpenCVE Enrichment