Impact
Vulnerability in the Oracle Hyperion Infrastructure Technology product allows an unauthenticated attacker to compromise the system over HTTP, potentially exposing critical data. The flaw resides in the Lifecycle Management component and results in confidentiality violations only, since the CVSS vector indicates no integrity or availability impact. The vulnerability is readily exploitable for unauthorized data access, as the attacker does not need credentials or user interface interaction.
Affected Systems
The affected system is Oracle Corporation's Hyperion Infrastructure Technology, specifically version 11.2.25.0.000. This version of the product is susceptible to the reported flaw.
Risk and Exploitability
With a CVSS score of 7.5, the vulnerability is considered high severity. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. An attacker with network access can exploit this flaw without authentication, directly over HTTP, to read sensitive data. The risk is elevated for environments that expose the Hyperion service to untrusted networks or lack additional access controls.
OpenCVE Enrichment