Impact
The vulnerability in Oracle Hyperion Financial Management 11.2.26.0.000 allows an unauthenticated attacker to gain unauthorized access to critical financial data over HTTP. Based on the description, the flaw appears to be an authentication bypass leading to broken access control, which permits reading, updating, inserting, or deleting data that should be protected. The impact includes loss of confidentiality and limited integrity, enabling the attacker to alter or leak sensitive information.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000. The product is deployed on Oracle Hyperion platforms and is vulnerable via its security component exposed over HTTP.
Risk and Exploitability
The CVSS v3.1 base score of 8.2 indicates a high confidentiality impact with low integrity loss. The EPSS score of < 1% reflects a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw using only network access to the HTTP interface; no credentials or user interaction is required, making the threat vector widely accessible to any network user.
OpenCVE Enrichment