Impact
A vulnerability in Oracle Hyperion Financial Management allows an unauthenticated attacker with network access over TLS to compromise the system. Successful exploitation leads to unauthorized creation, deletion, or modification of critical data and full access to all accessible data. The flaw enables a breach of confidentiality and integrity without requiring user interaction or elevated privileges.
Affected Systems
Oracle Corporation, Oracle Hyperion Financial Management, version 11.2.26.0.000. No other versions or products are listed as affected.
Risk and Exploitability
The CVSS v3.1 score of 7.4 indicates high severity, with poor confidentiality and integrity impact. The EPSS score of less than 1% shows a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The threat vector appears to be network-based over TLS, requiring no authentication. Because the attack path is relatively difficult to exploit, the overall immediate risk is moderate, but the potential damage warrants timely remediation.
OpenCVE Enrichment