Impact
A vulnerability in the Security component of Oracle Hyperion Financial Management allows a remote attacker with high privileges and network access via HTTP to compromise the system. The flaw can lead to unauthorized access to critical or all accessible data, and allows an attacker to cause a partial denial of service. The weakness is a privilege escalation or improper access control flaw, reflected in the CVSS 3.1 vector AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L, giving confidentiality high impact and availability low impact.
Affected Systems
Affected systems are Oracle Hyperion Financial Management version 11.2.26.0.000, delivered by Oracle Corporation. The vulnerability applies only to this version unless newer editions include the same issue, which is not documented in the advisory.
Risk and Exploitability
The CVSS base score of 7.6 indicates a high‑severity vulnerability. The EPSS score of less than 1 % shows a very low probability of exploitation in the current pool of active threats, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the attack vector is network accessible HTTP traffic, a high‑privileged attacker can exploit the flaw with low complexity and no user interaction, potentially gaining full data access or a partial denial of service. The scope change increases the attack surface, giving the attacker broader impact beyond the originally confined scope.
OpenCVE Enrichment