Impact
The vulnerability resides in the Security component of Oracle Hyperion Financial Management and allows an unauthenticated attacker with network access via HTTP to perform unauthorized creation, deletion, or modification of critical financial data. It also enables the attacker to rear partial denial of service, affecting availability. The impact is limited to integrity and availability, reflected in a CVSS 3.1 Base Score of 7.1.
Affected Systems
Oracle Corporation’s Hyperion Financial Management version 11.2.26.0.000 is affected. No other versions are listed as impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high risk to data integrity and modest availability impact. With an EPSS score of less than 1% and no listing in CISA’s KEV catalog, exploitation probability remains low but non‑negligible. The attack vector is network‑based via HTTP, requiring no authentication but human interaction from a third party to accomplish the attack. The combination of unauthenticated access and the need for human interaction reduces overall exploitability but does not negate the risk of significant data compromise or service disruption.
OpenCVE Enrichment