Impact
A vulnerability in the security component of Oracle Hyperion Financial Management enables an attacker with network access to the HTTP interface to establish high privileged access and fully compromise the application. The flaw appears to be due to improper access control or authentication bypass, which is inferred from the fact that an attacker can send crafted requests and gain full control. Successful exploitation would allow full takeover of the Hyperion environment, compromising confidentiality, integrity, and availability of financial data.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000, part of Oracle’s Hyperion suite, is affected. The vulnerability is limited to this specific version of the Hyperion Financial Management application.
Risk and Exploitability
The CVSS v3.1 base score of 7.2 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) indicates a medium‑to‑high severity. The EPSS score of less than 1% suggests current exploitation activity is low, and the vulnerability is not listed in CISA’s KEV catalog. Attackers can remotely exploit the flaw by issuing malicious HTTP requests to privileged endpoints, potentially leading to a full system takeover if the vulnerable version remains exposed.
OpenCVE Enrichment