Impact
The vulnerability resides in the Security component of Oracle Hyperion Financial Management and allows an unauthenticated attacker with network access via HTTP to compromise the application. Successful exploitation can lead to a full takeover of the system, resulting in loss of confidentiality, integrity and availability of the financial data and services. The CVSS vector shows that no privileged user is required and no user interaction is needed, highlighting the seriousness of the flaw.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000 is affected. No other versions or products are listed in the advisory.
Risk and Exploitability
The CVSS base score of 8.1 reflects high severity. The EPSS score is below 1%, indicating that exploitation is unlikely but still possible. The vulnerability is not currently listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a remote, unauthenticated HTTP request that takes advantage of the flawed Security component to gain full control of the application.
OpenCVE Enrichment