Impact
A weakness in the security component of Oracle Hyperion Financial Management allows a low‑privileged attacker with network access over HTTP to compromise the application. If successfully exploited, the attacker can take full control, leading to loss of confidentiality, integrity and availability of the financial management system.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000 supplied by Oracle Corporation.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates high severity with full impact on confidentiality, integrity and availability. The EPSS score is below 1 %, implying a low current probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can target the publicly reachable HTTP interface, crafting requests that trigger the compromise of the application.
OpenCVE Enrichment