Impact
A vulnerability in Oracle Hyperion Financial Management allows a low‑privileged attacker with network access via HTTP to bypass access controls, resulting in unauthorized access to critical data or even full access to all data managed by the application, along with the potential to cause a partial denial of service. The flaw relies on improper authorization checks in a security component, providing high confidentiality impact with a moderate availability impact as indicated by the CVSS score of 7.1.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000 is affected. The vulnerability is present in the security component of this product and affects installations that expose the HTTP interface to the network.
Risk and Exploitability
The CVSS vector:L/UI:N) reflects a network vulnerability that is easily exploitable for a low‑privileged attacker. The EPSS score of less than 1 % suggests that, while the vulnerability is present, exploitation activity may be limited. The vulnerability is not listed in the CISA KEV catalog. An attacker could leverage the exposed HTTP service to exploit the bug, gain unauthorized access, and possibly disrupt services. Monitoring for suspicious HTTP traffic and restricting access are advised.
OpenCVE Enrichment