Impact
A vulnerability in the Security component of Oracle Hyperion Financial Management allows an unauthenticated attacker with network access via HTTP to compromise the application. The flaw enables the creation, deletion or modification of critical data as well as unauthorized read access to a subset of the data. The result is a breach of confidentiality and integrity for information stored in the system.
Affected Systems
Oracle Hyperion Financial Management, version 11.2.26.0.000, is the only product affected by this vulnerability.
Risk and Exploitability
The CVSS 3.1 Base Score of 8.2 indicates a high severity with significant confidentiality and integrity impact. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, but the lack of authentication and exposed HTTP interface make it easily exploitable. Attackers can trigger the flaw by sending crafted HTTP requests from a remote location, and no further authentication or privilege is required to perform the malicious actions.
OpenCVE Enrichment