Impact
A vulnerability exists in the Oracle Hyperion Financial Management security component that allows an attacker who has high privileged access and network connectivity over HTTP to compromise the application. Successful exploitation can lead to a complete takeover, affecting the confidentiality, integrity, and availability of the financial data managed by the product.
Affected Systems
Oracle Hyperion Financial Management 11.2.26.0.000 is affected. The vulnerability specifically targets the 11.2.26.0.000 release of Oracle Hyperion Financial Management; no other versions are mentioned as affected.
Risk and Exploitability
The CVSS 3.1 score of 7.2 indicates a high severity with potential for significant damage. The EPSS score of less than 1% suggests a low probability of exploitation at this time, and the vulnerability is not listed in CISA's KEV catalog. The attack vector requires an attacker with high privileges and remote network access over HTTP. Successful exploitation can result in a complete takeover, impacting confidentiality, integrity, and availability of the application.
OpenCVE Enrichment