Impact
An easily exploitable vulnerability in Oracle Hyperion Financial Management enables an unauthenticated attacker with network access via HTTP to compromise the system, allowing unauthorized creation, deletion or modification of critical data and granting full access to all accessible data. The flaw earns a CVSS 3.1 base score of 10.0, indicating severe confidentiality and integrity impacts with a scope change. Successful exploitation can therefore lead to data tampering and unauthorized data exfiltration.
Affected Systems
The vulnerable product is Oracle Hyperion Financial Management version 11.2.26.0.000. Only this version is listed as affected; the defect resides in the Security component of the product.
Risk and Exploitability
The CVSS score of 10.0 signals maximum severity, while the EPSS score of less than 1% indicates that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, meaning no widespread exploits are documented, but the potential impact is high. The attack vector is a network-based HTTP connection from an unauthenticated attacker, requiring no prior authentication and providing remote access that may also affect other Oracle products if the scope changes.
OpenCVE Enrichment