Impact
A vulnerability in the security component of Oracle Hyperion Financial Management allows a low‑privileged attacker with network access via HTTP to compromise the system. When exploited, the attacker can take full control of the application, resulting in loss of confidentiality, integrity, and availability for all data managed by the platform. The weakness is described as difficult to exploit, yet the CVSS vector indicates the potential for a complete takeover.
Affected Systems
The affected product is Oracle Hyperion Financial Management, version 11.2.26.0.000, provided by Oracle Corporation.
Risk and Exploitability
The vulnerability has a CVSS 3.1 base score of 7.5, indicating high severity, but the EPSS score is less than 1% which suggests that it is unlikely to be widely exploited at this time. It is not listed in the CISA KEV catalog. The described attack vector requires network access over HTTP and a low‑privileged account; no user interaction is needed, so the risk from reconnaissance and credentialed access is significant if the system is exposed to untrusted networks.
OpenCVE Enrichment