Impact
The vulnerability in Oracle Hyperion Financial Management allows an attacker with low privileges and network access via HTTP to perform unauthorized creation, deletion or modification of data, and potentially gain complete access to all data managed by the application. This flaw demonstrates a severe confidentiality and integrity impact, as indicated by the CVSS vector of high impact on confidentiality and integrity while availability remains unaffected. The issue is rooted in improper privilege or access control, permitting low‑privileged users to act with higher levels of authority than intended.
Affected Systems
Oracle Corporation’s Hyperion Financial Management product, version 11.2.26.0.000, is the only affected release. This version is explicitly identified in the vendor’s security alert and CPE string.
Risk and Exploitability
With a CVSS score of 8.1 the vulnerability is considered high severity. The EPSS score is less than 1 %, indicating a currently low but non‑zero probability of exploitation. The issue is not listed in CISA’s KEV catalog, which suggests it is not widely exploited at this time. Attackers would need to target the application over an unsecured HTTP connection and have a low‑privilege account or credential; from there they can exploit improper access control to elevate privileges and compromise data. Combinations of network access, application flaws and inadequate privileges make the context of exploitation plausible, yet the likelihood remains modest according to EPSS.
OpenCVE Enrichment