Impact
The vulnerability resides in the Security component of Oracle Hyperion Financial Management. A low‑privileged attacker who can reach the application via HTTP could exploit the flaw, requiring a secondary user interaction to fully compromise the system. Successful exploitation leads to unauthorized reading of critical data and, in some cases, full data access, as well as unauthorized insert, update or delete operations, thereby impacting both confidentiality and integrity of financial records.
Affected Systems
Oracle Corporation’s Hyperion Financial Management version 11.2.26.0.000. No other affected products or versions are listed.
Risk and Exploitability
With a CVSS 3.1 base score of 7.6, this issue is considered high severity. The EPSS score of < 1% and the fact that it is not listed in CISA’s KEV catalog indicate a low current exploitation probability. The scope change and requirement for a human user suggest that the vulnerability could have a lasting impact, though this is inferred from the description. The attack vector is likely via HTTP, targeting a low‑privileged user on the network, which is inferred from the stated need for network access via HTTP.
OpenCVE Enrichment